CVE-2026-47292
Visual Studio Code MSSQL Extension Remote Code Execution Vulnerability
Description
Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
In plain language
AI Act nowA security flaw in the Visual Studio Code MSSQL Extension could let an attacker run harmful code on a computer running VS Code if the attacker can get you to interact with something—this is a serious issue (RED), so you should update.
CVE-2026-47292 is a local remote code execution risk in the Visual Studio Code MSSQL Extension caused by inclusion of untrusted functionality, enabling an attacker to execute arbitrary code on the local system without needing authentication but requiring user interaction.
What to do now
- Check your installed Visual Studio Code version and the Visual Studio Code - MSSQL Extension version currently installed.
- Update Visual Studio Code - MSSQL Extension to version 1.123.2 or later.
- Update Visual Studio Code to version 1.123.1 or later.
- After updating, restart Visual Studio Code and confirm the MSSQL Extension version shows the updated number.
- Avoid opening VS Code content (extensions/tools, imported projects, or prompts) from untrusted sources until updates are applied.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
- Rapid7en·Rapid7 Blog· Roundup Windows Nightmare Eclipse
- Microsoft June 2026 Patch Tuesday fixes 3 zero-day, 200 flawsen-us·BleepingComputer· Patch Windows Collaborative Translation Framework (CTFMON) patch-tuesday
- Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flawsen-us·BleepingComputer· Exploited Windows Collaborative Translation Framework (CTFMON) Nightmare Eclipse
- Microsoft June 2026 Patch Tuesday - SANS Internet Storm Centeren·SANS Internet Storm Center· Exploited Microsoft Windows patch-tuesday
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-47292 and every CVE in our database. Create a free account — no credit card required.
Create Free Account