CVE-2020-0604 is a remote code execution vulnerability affecting Microsoft Visual Studio Code. It allows an attacker to execute arbitrary code by manipulating environment variables when a user opens a malicious project. This vulnerability carries a high severity CVSS score of 8.8, indicating a network-based attack with low complexity, requiring user interaction, and potentially leading to full system compromise. While no public exploit code is available and it is not listed in CISA's KEV catalog, there has been some community discussion and media coverage, suggesting awareness of the flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.24.0CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_code:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.