Vulnerability record · CVE-2021-28472 · published 13 April 2021
CVE-2021-28472: Microsoft VS Code Maven for Java Extension Remote Code Execution
Microsoft · Vscode Maven
The Maven for Java extension for Visual Studio Code contains a remote code execution flaw. The record gives no root-cause detail beyond the CWE being unclassified, so the exact vulnerable mechanism is not stated. It matters because code execution in a developer's editor can compromise source code, credentials and build pipelines.
Description
Visual Studio Code Maven for Java Extension Remote Code Execution Vulnerability
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityHigh CVSS impact with a very high EPSS percentile, though exploitation requires local user interaction and no KEV listing exists.
What it is
The Maven for Java extension for Visual Studio Code contains a remote code execution flaw. The record gives no root-cause detail beyond the CWE being unclassified, so the exact vulnerable mechanism is not stated. It matters because code execution in a developer's editor can compromise source code, credentials and build pipelines.
Impact
An attacker who gets the crafted input in front of the victim can execute code in the context of the VS Code process, gaining the victim's file and credential access. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
The vector is local (AV:L) with user interaction required (UI:R) and no privileges required (PR:N), meaning the victim must open or interact with a malicious project, file or extension input. No authentication is needed, but the attack is not remotely reachable without that user action.
Exploitation
Not listed in CISA KEV, so no confirmed in-the-wild exploitation is recorded. EPSS is high at roughly 0.62 (99th percentile), indicating elevated predicted likelihood, and the only references are Microsoft patch advisories.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2021-28472.
- Update the Maven for Java extension and Visual Studio Code to current supported versions.
- Treat untrusted repositories, workspaces and Maven project files as hostile; open them only in a sandboxed or isolated environment.
- Restrict extension permissions and review installed VS Code extensions against an approved list.
- Monitor developer endpoints for unexpected child processes spawned by VS Code.
Detection
- Alert on VS Code or its extension host spawning shells, scripting interpreters or build tools outside normal developer workflow.
- Audit VS Code extension inventory and versions across developer endpoints for the affected Maven for Java extension.
- Review endpoint telemetry for suspicious file writes or network connections originating from the VS Code process after opening an untrusted workspace.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-28472 | PatchVendor Advisory |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-28472 | PatchVendor Advisory |
Track CVE-2021-28472 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2021-28472), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.