4.3
CVSSv2

CVE-2021-43908

Published: 15/12/2021 Updated: 01/01/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Visual Studio Code Spoofing Vulnerability

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft visual studio code -

Vendor Advisories

A content spoofing vulnerability has been found in Visual Studio Code ...

Github Repositories

Trying to reproduce CVE-2021-43908

vscode-rce-electrovolt CVE-2021-43908 blogelectrovoltio/posts/vscode-rce/

Electron Research

Electron Research Title: TBA Intro The following research will be published in an upcoming conference During the end of prototype pollution research, BlackFan and I came across a Prototype Pollution XSS in a web application that has a Desktop Application using ~Electron So, I tried to escalate it to Remote Code Execution in the Desktop App and eventually I was able to get Rem