NCSC-2026-0351 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Developer Tools
Microsoft heeft 15 kwetsbaarheden verholpen in diverse Developer Tools. Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de categorieën schade zoals benoemd in onderstaande tabel. De ernstigste kwetsbaarheid met kenmerk CVE-2026-81376 heeft een CVSS-score van 9,6. Een kwaadwillende misbruiken door een gebruiker ertoe te verleiden een speciaal geprepareerde Visual Studio Code-workspace te openen. Hiermee kunnen de Workspace Trust-beperkingen worden omzeild, waardoor inhoud uit een niet-vertrouwde workspace opdrachten of code kan uitvoeren zonder dat de gebruiker hiervoor eerst toestemming geeft. Hierdoor kan de kwaadwillende toegang krijgen tot lokale gegevens of code uitvoeren met de rechten van de gebruiker. Voor succesvol misbruik moet de kwaadwillende het slachtoffer misleiden een malafide broncodebestand te importeren en verwerken.
.NET: |----------------|------|-------------------------------------| | CVE-ID | CVSS | Impact | |----------------|------|-------------------------------------| | CVE-2026-58649 | 6,50 | Toegang tot gevoelige gegevens | |----------------|------|-------------------------------------| GitHub Copilot and Visual Studio Code: |----------------|------|-------------------------------------| | CVE-ID | CVSS | Impact | |----------------|------|-------------------------------------| | CVE-2026-81380 | 5,30 | Toegang tot gevoelige gegevens | | CVE-2026-81381 | 6,50 | Toegang tot gevoelige gegevens | |----------------|------|-------------------------------------| Visual Studio Code: |----------------|------|-------------------------------------| | CVE-ID | CVSS | Impact | |----------------|------|-------------------------------------| | CVE-2026-70334 | 7,80 | Omzeilen van beveiligingsmaatregel | | CVE-2026-78461 | 7,40 | Omzeilen van beveiligingsmaatregel | | CVE-2026-78462 | 8,80 | Omzeilen van beveiligingsmaatregel | | CVE-2026-81356 | 8,20 | Omzeilen van beveiligingsmaatregel | | CVE-2026
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0351
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-81376 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58649 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-81380 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-81381 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-70334 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-78461 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-78462 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-81356 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-81357 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-81377 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-81378 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-81379 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-81383 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-57099 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-69304 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58611 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-80097 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [hoch] Microsoft Entwicklerwerkzeuge: Mehrere Schwachstellen ermöglichen Privilegieneskalationcert-bund
- unknownUSN-8740-1: .NET vulnerabilitiesubuntu
- mediumGHSA-8cp2-47hg-mfgh: Microsoft Security Advisory CVE-2026-69304 – ASP.NET Core Denial of Service Vulnerabilityghsa
- high[NEU] [hoch] Microsoft Apps: Mehrere Schwachstellen ermöglichen Privilegieneskalationcert-bund
- unknownMultiples vulnérabilités dans Microsoft .Net (09 septembre 2026)cert-fr-avis
- unknownMultiples vulnérabilités dans les produits Microsoft (09 septembre 2026)cert-fr-avis
- highCVE-2026-81383: Use of incorrectly-resolved name or reference in Visual Studio Code allows an unauthorized att…nvd
- mediumCVE-2026-81381: Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauth…nvd
- mediumCVE-2026-81380: Improper neutralization of special elements used in a command ('command injection') in GitHub …nvd
- highCVE-2026-81379: Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to…nvd
- highCVE-2026-81378: Interpretation conflict in Visual Studio Code allows an unauthorized attacker to bypass a secu…nvd
- mediumCVE-2026-81377: Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studi…nvd
Recent advisories for Kwetsbaarheden verholpen in
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownNCSC-2026-0365 [1.00] [H/H] Kwetsbaarheden verholpen in Check Point VPN productenncsc-nl · 2026-09-10
- unknownNCSC-2026-0364 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Illustratorncsc-nl · 2026-09-09
- unknownNCSC-2026-0363 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Experience Managerncsc-nl · 2026-09-09
- unknownNCSC-2026-0362 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe ColdFusionncsc-nl · 2026-09-09
- unknownNCSC-2026-0361 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Commercencsc-nl · 2026-09-09
- unknownNCSC-2026-0360 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Photoshop Desktopncsc-nl · 2026-09-09
More from NCSC-NL Advisories
- unknownNCSC-2026-0365 [1.00] [H/H] Kwetsbaarheden verholpen in Check Point VPN producten2026-09-10
- unknownNCSC-2026-0364 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Illustrator2026-09-09
- unknownNCSC-2026-0363 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Experience Manager2026-09-09
- unknownNCSC-2026-0362 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe ColdFusion2026-09-09
- unknownNCSC-2026-0361 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Commerce2026-09-09