CVE-2026-47292ImportantRevised 24 Sep
Visual Studio Code MSSQL Extension Remote Code Execution Vulnerability
Assessment
Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
- Severity
- Important
- CVSS base score
- 7.8CVSS:3.1/
AV:L/ AC:L/ PR:N/ UI:R/ S:U/ C:H/ I:H/ A:H/ E:U/ RL:O/ RC:C - Impact
- Elevation of Privilege
- EPSS, next 30 days
- 0.5%Higher than 37.6% of scored CVEs · FIRST model run 29 Sep 2026 · about EPSS
- Public exploit code
- No Nuclei template lists it
- Exploitability
- Exploitation Less Likely
- Publicly disclosed
- No
- Customer action
- Required: apply the update
- Component
- Visual Studio Code
- Weakness
- CWE-829: Inclusion of Functionality from Untrusted Control Sphere
- Issued by
- Microsoft
- Published
- 9 Jun 2026 · June 2026
- Last revised
- 24 Sep 2026Updated the fixed version information and download link. The fix was previously believed to be included in Dynamics 365 Server (on-premises) version 6.2; however, it has been confirmed that the fix is included in Dynamics 365 Server v9.1 (on-premises) Update 1.45 (version 9.1.0045.0011). The downlo…
Updates that fix it
0 KBsNo KB listed
MSRC lists no downloadable update, which usually means a service-side fix or a release-notes update. Check the MSRC advisory.