CVE-2021-43891 is a high-severity Remote Code Execution (RCE) vulnerability affecting Microsoft Visual Studio Code. With a CVSS score of 7.8, this flaw allows an attacker to execute arbitrary code on a vulnerable system, requiring user interaction but no prior privileges. While not currently listed on CISA's KEV catalog, its high EPSS score and FAUCET Risk Score of 81/100 indicate a significant potential for future exploitation. There is no public exploit code available (Metasploit, Nuclei, ExploitDB), and community discussion and media coverage are limited, suggesting it is not under active widespread exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.63.2CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_code:*:*:*:*:*:*:*:* | ||
>= 1.0.0, < 1.63.1CPE match | cpe:2.3:a:microsoft:visual_studio_code:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.