Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT Security Bulletin ASB-2019.0305 Privilege escalation flaw addressed in Visual Studio Code 18 October 2019 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: Visual Studio Code Operating System: Windows Impact/Access: Execute Arbitrary Code/Commands -- Existing Account Increased Privileges -- Existing Account Resolution: Patch/Upgrade CVE Names: CVE-2019-1414 Member content until: Sunday, November 17 2019 OVERVIEW Microsoft has published an update for Visual Studio Code to fix an exposed debug listener. [1] IMPACT Microsoft advises: "An elevation of privilege vulnerability exists in Visual Studio Code when it exposes a debug listener to users of a local computer. A local attacker who successfully exploited the vulnerability could inject arbitrary code to run in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights." [1] MITIGATION Microsoft advises updating to the latest version of Visual Studio Code to address this vulnerability. [1] REFERENCES [1] CVE-2019-1414 https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2019-1414 AusCERT has made every effort to ensure that the information contained in this document is accurate. However, the decision to use the information described is the responsibility of each user or organisation. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBXakM3WaOgq3Tt24GAQjBvBAAjUrwgUMd4rb1CskBFItDNHx/GDK6/dqG PPwM1VKmKFu0iKKWakQkygwGm/o2kiP86TeExdxtTwc62t/GSdeWXKdfNgAmmubj yuMpG5qf9b7Zfr3XqO7ejxbz2t3/iV+fEKcHcyIvyGe3MMrXHDEMVnyHdvku5Rcd RjEmEN2scw2K9um2QxFAyBn3LIdwlv5MXSjY0oB1IuoqWEG/2xWykTf+7z2/DbDD q2APLoXRdsKWmnRf3g1kIJldSgNxhUzf7n+FXCEkGAvHAF/fnJqNvQcqTm0s0Bu3 xg48xUdoxjwis8VcBxaQ5aPy85PTT5M4UrzMGno7MuxupJc9f1xB18+Jqx6AW+5/ 41P7/Kjc/GKHulXnUbVS2lbKWj93jmbCdYlkm/6f5w9chy1VNydsZLyDq1I6Nv1l ldBUklqI8sMnFtmtDmcHnYaJRuhlFgPC9gW0spXKPABMu7Uki/vKbSSKkCsPOHjl cla/mus568acXS7u5SYQQWMwyJr1GHW/qvolQk1YYpcLpCHecUqft7ot3pH2KIHA jbZavSm0PtaXZfMJJ+wGeKwYp3Zsix9dKdBzNK0gkaPB/TvzOAy90K7N7SKN4oFE w/unZdzFl8xr692nIuMYVFpE2/idjYb+/EFnUXqXhoh+1ACiQg+HRgqpJ3k7wJVx ICTGynT0pPo= =X1qx -----END PGP SIGNATURE-----