CVE-2024-49050

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Nov 12, 2024
Updated: Nov 13, 2024
CWE ID 501

Summary

CVE-2024-49050 is a newly disclosed vulnerability affecting Visual Studio Code's Python Extension. Maliciously crafted Python files can exploit this remote code execution flaw, enabling attackers to execute arbitrary code on impacted systems. Successful exploitation could lead to significant data loss or system compromise. Users are advised to update their extensions and apply additional security measures, such as input validation and sandboxing, to mitigate potential risks. Microsoft is currently working on a patch to address this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share