Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2020-1171— Visual Studio Code Python Extension Remote Code Execution Vulnerability

Quick assessment

Affected
Microsoft Python extension for Visual Studio Code
Exploitation
High exploitation probability; assess promptly
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Microsoft Visual Studio Code是美国微软(Microsoft)公司的一款开源的代码编辑器。 Microsoft Visual Studio Code中Python扩展加载配置文件的过程存在远程代码执行漏洞。攻击者可通过诱使用户复制资源库并在Visual Studio Code中将其打开利用该漏洞在当前用户的上下文中运行任意代码。以下产品及版本受到影响: Visual Studio Code版本。

AI Predicted 9.8 Difficulty: Easy EPSS 5.17% · P92

Affected Version Matrix 1

VendorProduct Version RangeStatus
Microsoft Python extension for Visual Studio Code 2020< publication affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2020-1171

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Visual Studio Code Python Extension Remote Code Execution Vulnerability
Source: CVE Program / CVE List V5
Vulnerability Description
A remote code execution vulnerability exists in Visual Studio Code when the Python extension loads configuration files after opening a project. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would need to convince a target to clone a repository and open it in Visual Studio Code with the Python extension installed. Attacker-specified code would execute when the target opened the integrated terminal. The update address the vulnerability by modifying the way Visual Studio Code Python extension handles environment variables.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Microsoft Visual Studio Code 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Microsoft Visual Studio Code是美国微软(Microsoft)公司的一款开源的代码编辑器。 Microsoft Visual Studio Code中Python扩展加载配置文件的过程存在远程代码执行漏洞。攻击者可通过诱使用户复制资源库并在Visual Studio Code中将其打开利用该漏洞在当前用户的上下文中运行任意代码。以下产品及版本受到影响: Visual Studio Code版本。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Microsoft Python extension for Visual Studio Code 2020 ~ publication -

II. Public POCs for CVE-2020-1171

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2020-1171

请登录查看更多情报信息。

Vendor Advisories for CVE-2020-1171 (2)

Same Patch Batch · Microsoft · 2020-05-21 · 112 CVEs total

CVE-2020-1117 8.8 HIGH Microsoft Color Management Remote Code Execution Vulnerability
CVE-2020-1126 8.8 HIGH Media Foundation Memory Corruption Vulnerability
CVE-2020-1118 8.6 HIGH Microsoft Windows Transport Layer Security Denial of Service Vulnerability
CVE-2020-1112 8.5 HIGH Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability
CVE-2020-1086 7.8 HIGH Windows Runtime Elevation of Privilege Vulnerability
CVE-2020-1077 7.8 HIGH Windows Runtime Elevation of Privilege Vulnerability
CVE-2020-1078 7.8 HIGH Windows Installer Elevation of Privilege Vulnerability
CVE-2020-1142 7.8 HIGH Windows GDI Elevation of Privilege Vulnerability
CVE-2020-1082 7.8 HIGH Windows Error Reporting Elevation of Privilege Vulnerability
CVE-2020-1139 7.8 HIGH Windows Runtime Elevation of Privilege Vulnerability
CVE-2020-1140 7.8 HIGH DirectX Elevation of Privilege Vulnerability
CVE-2020-1137 7.8 HIGH Windows Push Notification Service Elevation of Privilege Vulnerability
CVE-2020-1081 7.8 HIGH Windows Printer Service Elevation of Privilege Vulnerability
CVE-2020-1135 7.8 HIGH Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2020-1136 7.8 HIGH Media Foundation Memory Corruption Vulnerability
CVE-2020-1079 7.8 HIGH Microsoft Windows Elevation of Privilege Vulnerability
CVE-2020-1110 7.8 HIGH Windows Update Stack Elevation of Privilege Vulnerability
CVE-2020-1090 7.8 HIGH Windows Runtime Elevation of Privilege Vulnerability
CVE-2020-1109 7.8 HIGH Windows Update Stack Elevation of Privilege Vulnerability
CVE-2020-1114 7.8 HIGH Windows Kernel Elevation of Privilege Vulnerability

Showing top 20 of 112 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2020-1171

No comments yet


Leave a comment