Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-40750 | Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code execution through network attack vector. |
Tue, 10 Dec 2024 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs |
Mon, 21 Oct 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:microsoft:visual_studio_code:-:*:*:*:*:*:*:* |
Tue, 08 Oct 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Oct 2024 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code execution through network attack vector. | |
| Title | Visual Studio Code extension for Arduino Remote Code Execution Vulnerability | |
| First Time appeared |
Microsoft
Microsoft visual Studio Code |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:a:microsoft:visual_studio_code:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Microsoft
Microsoft visual Studio Code |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2025-07-08T15:39:38.489Z
Reserved: 2024-08-14T01:08:33.520Z
Link: CVE-2024-43488
Updated: 2024-10-08T19:21:46.215Z
Status : Analyzed
Published: 2024-10-08T18:15:11.030
Modified: 2024-10-21T21:05:53.340
Link: CVE-2024-43488
No data.
OpenCVE Enrichment
No data.
EUVD