10
CVSSv2

CVE-2021-43907

Published: 15/12/2021 Updated: 01/01/2022
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 891
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Visual Studio Code WSL Extension Remote Code Execution Vulnerability

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows subsystem for linux

Github Repositories

Proof of Concept for CVE-2021-43891

Proof of Concept for VS Code Remote WSL Remote Code Execution - CVE-2021-43907 See the blog at parsiyanet/blog/2021-12-20-rce-in-visual-studio-codes-remote-wsl-for-fun-and-negative-profit Also msrcmicrosoftcom/update-guide/vulnerability/CVE-2021-43907 Building npm install Store vsdanode for your architecture in /routes/vsdanode Run npm start or use ctr

Contains random code and some of my older projects

Random Code This repository contains most of the code that I write for my blog posts I realized I have random repositories on Github I am consolidating them into one Individual Licenses Most code in this repository is governed under the MIT Some code may have a different license, check each directory for a license file Security Code Security code will be mostly in https

Recent Articles

Microsoft closes installer hole abused by Emotet malware, Google splats Chrome bug exploited in the wild
The Register • Chris Williams, Editor in Chief • 15 Dec 2021

Get our weekly newsletter Round off the year with a large crop of fixes for programming blunders

Patch Tuesday It's not just Log4j you need to worry about this week. It's the final Patch Tuesday of the year. If you haven't already installed these fixes, or started testing them ahead of deployment, now would be a good time before exploits are developed and deployed over the Christmas break. At least two of them – one in Windows AppX Installer and one in Chrome – are being exploited in the wild right now. Let's start with Microsoft, which put out a summary of its security updates here. Al...