Advisory #16
TitleC/C++ Advanced Lint for VS Code remote code execution via crafted workspace configuration
CVE IDCVE-2021-28953
VendorJoseph Benden
Affected productC/C++ Advanced Lint for VS Code
Affected versions- v1.8.2
Vulnerability typeCWE-284 (Improper Access Control)
DescriptionC/C++ Advanced Lint for VS Code has a vulnerability that allows a crafted workspace folder to execute arbitrary binaries, which leads remote code execution.
StatusFixed in v1.9.0
RecommendationUpdate to v1.9.0 or above