Vulnerability record · CVE-2021-27084 · published 11 March 2021
CVE-2021-27084: Visual Studio Code Java Extension Pack remote code execution
Microsoft · Maven For Java
CVE-2021-27084 is a remote code execution flaw in the Microsoft Visual Studio Code Java Extension Pack (listed product: maven_for_java). The record gives only a one-line description and no root-cause detail, so the exact vulnerable component and mechanism are not stated. It matters because successful exploitation yields full compromise of confidentiality, integrity and availability on the affected developer machine.
Description
Visual Studio Code Java Extension Pack Remote Code Execution Vulnerability
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8 with full confidentiality, integrity and availability impact plus a very high EPSS score, though exploitation requires local user interaction and no KEV listing exists.
What it is
CVE-2021-27084 is a remote code execution flaw in the Microsoft Visual Studio Code Java Extension Pack (listed product: maven_for_java). The record gives only a one-line description and no root-cause detail, so the exact vulnerable component and mechanism are not stated. It matters because successful exploitation yields full compromise of confidentiality, integrity and availability on the affected developer machine.
Impact
An attacker who gets code executed gains high impact across confidentiality, integrity and availability, meaning arbitrary code execution in the context of the VS Code user. That typically means access to source code, credentials and the developer's local environment.
Attack surface
The CVSS vector is local (AV:L) with user interaction required (UI:R) and no privileges required (PR:N), so the attack is reached by getting the victim to open or interact with crafted content in the IDE rather than over the network directly. No authentication is needed, but the victim must perform the triggering interaction.
Exploitation
The record shows no CISA KEV listing and no exploit-tagged references, so there is no confirmed in-the-wild exploitation; EPSS is high at 0.62127 (99.1st percentile), indicating elevated predicted likelihood of exploitation activity.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2021-27084 as the first action.
- Update the Visual Studio Code Java Extension Pack and its bundled Maven for Java component to the fixed release.
- Restrict developers from opening untrusted workspaces, projects or build files in VS Code until patched.
- Enforce VS Code Workspace Trust so untrusted folders cannot auto-execute extension or build tasks.
- Monitor extension and Maven-related processes spawned by VS Code for unexpected child processes.
Detection
- Alert on VS Code or Java extension processes spawning shells, scripting hosts or other unexpected child processes.
- Monitor for new or modified files in VS Code extension directories and workspace .vscode task or settings files.
- Review endpoint telemetry for Maven or Java build tasks executing outside normal developer workflows.
- Correlate developer workstation process creation events with recent opening of untrusted workspaces or repositories.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-27084 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2021-27084), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.