← Vulnerability feed

Vulnerability record · CVE-2021-28472 · published 13 April 2021

CVE-2021-28472: Microsoft VS Code Maven for Java Extension Remote Code Execution

Microsoft · Vscode Maven

The Maven for Java extension for Visual Studio Code contains a remote code execution flaw. The record gives no root-cause detail beyond the CWE being unclassified, so the exact vulnerable mechanism is not stated. It matters because code execution in a developer's editor can compromise source code, credentials and build pipelines.

7.8 CVSS 3.1 High EPSS 62% · top 0.9%
7.8CVSS 3.1 base score, v2 6.8
62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Visual Studio Code Maven for Java Extension Remote Code Execution Vulnerability

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityHigh CVSS impact with a very high EPSS percentile, though exploitation requires local user interaction and no KEV listing exists.

What it is

The Maven for Java extension for Visual Studio Code contains a remote code execution flaw. The record gives no root-cause detail beyond the CWE being unclassified, so the exact vulnerable mechanism is not stated. It matters because code execution in a developer's editor can compromise source code, credentials and build pipelines.

Impact

An attacker who gets the crafted input in front of the victim can execute code in the context of the VS Code process, gaining the victim's file and credential access. The CVSS vector rates confidentiality, integrity and availability impact as high.

Attack surface

The vector is local (AV:L) with user interaction required (UI:R) and no privileges required (PR:N), meaning the victim must open or interact with a malicious project, file or extension input. No authentication is needed, but the attack is not remotely reachable without that user action.

Exploitation

Not listed in CISA KEV, so no confirmed in-the-wild exploitation is recorded. EPSS is high at roughly 0.62 (99th percentile), indicating elevated predicted likelihood, and the only references are Microsoft patch advisories.

What to do

  • Apply the Microsoft security update referenced in the MSRC advisory for CVE-2021-28472.
  • Update the Maven for Java extension and Visual Studio Code to current supported versions.
  • Treat untrusted repositories, workspaces and Maven project files as hostile; open them only in a sandboxed or isolated environment.
  • Restrict extension permissions and review installed VS Code extensions against an approved list.
  • Monitor developer endpoints for unexpected child processes spawned by VS Code.

Detection

  • Alert on VS Code or its extension host spawning shells, scripting interpreters or build tools outside normal developer workflow.
  • Audit VS Code extension inventory and versions across developer endpoints for the affected Maven for Java extension.
  • Review endpoint telemetry for suspicious file writes or network connections originating from the VS Code process after opening an untrusted workspace.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-28472 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2021-28472), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.