CERT-In Vulnerability Note
CIVN-2021-0373
Remote Code Execution Vulnerability in Microsoft Visual Studio Code WSL Extension
Original Issue Date:December 28, 2021
Severity Rating: HIGH
Software Affected
- Visual Studio Code WSL Extension
Overview
A vulnerability has been reported in Microsoft Visual Studio Code WSL Extension which could allow a remote attacker to execute arbitrary code on the targeted system.
Description
This Vulnerability exits in Microsoft Visual Studio Code WSL Extension due to an improper input validation. A remote attacker could exploit this vulnerability by convincing a victim to open a specially-crafted content.
Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code on the targeted system.
Solution
Apply appropriate updates as mentioned by vendor:
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-43907
Vendor Information
Microsoft
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-43907
References
Microsoft
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-43907
CVE Name
CVE-2021-43907
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|