CVE-2021-27084 describes a Remote Code Execution vulnerability within the Microsoft Visual Studio Code Java Extension Pack, specifically affecting the Maven for Java component. This high-severity vulnerability, rated 7.8 CVSS, can be exploited with low attack complexity through user interaction, potentially leading to complete compromise of confidentiality, integrity, and availability. While not listed on the KEV catalog or having public exploit code like Metasploit or ExploitDB, it received limited community discussion and media coverage, primarily noted during Microsoft's March 2021 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:maven_for_java:-:*:*:*:*:visual_studio_code:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.