A remote code execution vulnerability exists in Microsoft Visual Studio Code when a user is tricked into opening a malicious package.json file. An attacker who successfully exploits this vulnerability could execute arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take complete control of the affected system, including the ability to install programs, view, change, or delete data, or create new accounts with full user rights.
To exploit this vulnerability, an attacker would need to convince a target to clone a repository and open it in Visual Studio Code. The attacker-specified code would execute when the target opens the malicious package.json file, making this a social engineering-dependent attack vector.
Successful exploitation allows arbitrary code execution with the privileges of the current user, potentially leading to full system compromise if the user has administrative rights.
This vulnerability represents a code injection attack targeting Visual Studio Code's JSON file parsing functionality. When VS Code processes a package.json file, improper handling of the file contents allows specially crafted data to trigger code execution. The attack requires user interaction, specifically opening a malicious file within the VS Code environment, making it a local attack vector that relies on social engineering techniques.
The impact is severe because developers frequently clone repositories from various sources and open them in VS Code without thorough inspection. The package.json file is a ubiquitous component of Node.js and npm projects, making it an ideal attack vector as it's typically one of the first files examined when reviewing a new project.
The root cause of this vulnerability lies in the way Visual Studio Code handles and processes JSON files, specifically package.json . The application failed to properly sanitize or validate the contents of these configuration files before processing them, allowing malicious payloads embedded within the JSON structure to execute code. Microsoft addressed this by modifying how Visual Studio Code handles JSON files to prevent arbitrary code execution during file parsing.
The attack vector requires an attacker to craft a malicious repository containing a specially crafted package.json file. The attack sequence proceeds as follows:
This local attack vector requires user interaction but has a low attack complexity once the victim opens the malicious file. The vulnerability does not require any prior privileges on the target system.
Microsoft has released a security update that addresses this vulnerability by modifying the way Visual Studio Code handles JSON files. Users should update to the latest version of Visual Studio Code through the built-in update mechanism or by downloading the latest installer from the official Microsoft website. For detailed patch information, refer to the Microsoft Security Advisory CVE-2020-17023 .
Disclaimer : This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
