Visual Studio Code Remote Code Execution Vulnerability - CVE-2019-0728 (Mac OS)ID: oval:org.secpod.oval:def:91194 | Date: (C)2023-07-20 (M)2023-12-03 |
Class: VULNERABILITY | Family: macos |
The host is installed with Visual Studio code before 1.31.1 and is prone to a remote code execution vulnerability. A flaw is present in the application, which fails to properly handle environment variables. Successful exploitation could allow attackers to run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
Platform: |
Apple Mac OS 14 |
Apple Mac OS X 10.15 |
Apple Mac OS X 10.10 |
Apple Mac OS X 10.11 |
Apple Mac OS X 10.12 |
Apple Mac OS X 10.13 |
Apple Mac OS X 10.14 |
Apple Mac OS 11 |
Apple Mac OS 12 |
Apple Mac OS 13 |
Product: |
Microsoft Visual Studio Code |