First published: Thu Nov 15 2018(Updated: )
A remote code execution vulnerability exists when Team Foundation Server (TFS) does not enable basic authorization on the communication between the TFS and Search services, aka "Team Foundation Server Remote Code Execution Vulnerability." This affects Team.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Team Foundation Server | =2018-1.1 | |
Microsoft Team Foundation Server | =2018-3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8529 is a remote code execution vulnerability in Team Foundation Server (TFS) when basic authorization is not enabled on the communication between TFS and Search services.
CVE-2018-8529 affects Team Foundation Server by allowing remote code execution when basic authorization is not enabled between TFS and Search services.
CVE-2018-8529 has a severity rating of 9.8 (Critical).
To fix CVE-2018-8529, enable basic authorization on the communication between Team Foundation Server (TFS) and Search services.
More information about CVE-2018-8529 can be found at the following references: [http://www.securityfocus.com/bid/105910](http://www.securityfocus.com/bid/105910) and [https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8529](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8529).