← Vulnerability feed

Vulnerability record · CVE-2021-27084 · published 11 March 2021

CVE-2021-27084: Visual Studio Code Java Extension Pack remote code execution

Microsoft · Maven For Java

CVE-2021-27084 is a remote code execution flaw in the Microsoft Visual Studio Code Java Extension Pack (listed product: maven_for_java). The record gives only a one-line description and no root-cause detail, so the exact vulnerable component and mechanism are not stated. It matters because successful exploitation yields full compromise of confidentiality, integrity and availability on the affected developer machine.

7.8 CVSS 3.1 High EPSS 62% · top 0.8%
7.8CVSS 3.1 base score, v2 9.3
62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
19 Aug 2026Last modified by NVD

Description

Visual Studio Code Java Extension Pack Remote Code Execution Vulnerability

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityCVSS 7.8 with full confidentiality, integrity and availability impact plus a very high EPSS score, though exploitation requires local user interaction and no KEV listing exists.

What it is

CVE-2021-27084 is a remote code execution flaw in the Microsoft Visual Studio Code Java Extension Pack (listed product: maven_for_java). The record gives only a one-line description and no root-cause detail, so the exact vulnerable component and mechanism are not stated. It matters because successful exploitation yields full compromise of confidentiality, integrity and availability on the affected developer machine.

Impact

An attacker who gets code executed gains high impact across confidentiality, integrity and availability, meaning arbitrary code execution in the context of the VS Code user. That typically means access to source code, credentials and the developer's local environment.

Attack surface

The CVSS vector is local (AV:L) with user interaction required (UI:R) and no privileges required (PR:N), so the attack is reached by getting the victim to open or interact with crafted content in the IDE rather than over the network directly. No authentication is needed, but the victim must perform the triggering interaction.

Exploitation

The record shows no CISA KEV listing and no exploit-tagged references, so there is no confirmed in-the-wild exploitation; EPSS is high at 0.62127 (99.1st percentile), indicating elevated predicted likelihood of exploitation activity.

What to do

  • Apply the Microsoft security update referenced in the MSRC advisory for CVE-2021-27084 as the first action.
  • Update the Visual Studio Code Java Extension Pack and its bundled Maven for Java component to the fixed release.
  • Restrict developers from opening untrusted workspaces, projects or build files in VS Code until patched.
  • Enforce VS Code Workspace Trust so untrusted folders cannot auto-execute extension or build tasks.
  • Monitor extension and Maven-related processes spawned by VS Code for unexpected child processes.

Detection

  • Alert on VS Code or Java extension processes spawning shells, scripting hosts or other unexpected child processes.
  • Monitor for new or modified files in VS Code extension directories and workspace .vscode task or settings files.
  • Review endpoint telemetry for Maven or Java build tasks executing outside normal developer workflows.
  • Correlate developer workstation process creation events with recent opening of untrusted workspaces or repositories.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-27084 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2021-27084), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.