CVE-2023-36742 is a high-severity Remote Code Execution vulnerability affecting Microsoft Visual Studio Code. An attacker could exploit this vulnerability locally, requiring user interaction, to achieve high impact on confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog or having public exploit code, it has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.82.1CPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_code:*:*:*:*:*:*:*:* | ||
>= 1.0.0, < 1.82.1CPE match | cpe:2.3:a:microsoft:visual_studio_code:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.