TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Remote Code Execution Vulnerability Discovered in Visual Studio Code

14 pointsby robin0about 6 years ago

1 comment

lioetersabout 6 years ago
VSCode version 1.31 in January 2019 included a security update to address this issue.<p>The following is a more direct link with pertinent info: <a href="https:&#x2F;&#x2F;portal.msrc.microsoft.com&#x2F;en-US&#x2F;security-guidance&#x2F;advisory&#x2F;CVE-2019-0728" rel="nofollow">https:&#x2F;&#x2F;portal.msrc.microsoft.com&#x2F;en-US&#x2F;security-guidance&#x2F;ad...</a><p>The heart of it is: &quot;To exploit this vulnerability, an attacker would need to convince a target to clone a repository and open it in Visual Studio Code. Attacker-specified code would execute when the target opened the integrated terminal.&quot;
评论 #19320457 未加载