Skip to content

Elevation of privilege in .NET Education Bundle SDK Install Tool

Moderate
sfoslund published GHSA-8p5g-gm8f-2vcw Jul 13, 2021

Package

vscode-dotnet-sdk (Visual Studio Marketplace)

Affected versions

-0.6.0

Patched versions

0.7.0-

Description

Impact

Due to inaccurately scoped permissions being set on downloaded .NET install scripts, users are vulnerable to an elevation of privileges attack.

Patches

This problem has been patched in version 0.7.0.

Resources

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34477

For more information

If you have any questions or comments about this advisory:

Severity

Moderate

CVE ID

CVE-2021-34477

Weaknesses

No CWEs