First published: Mon Jul 15 2019(Updated: )
A remote code execution vulnerability exists when Azure DevOps Server and Team Foundation Server (TFS) improperly handle user input, aka 'Azure DevOps Server and Team Foundation Server Remote Code Execution Vulnerability'.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Team Foundation Server | =2010-sp1 | |
Microsoft Team Foundation Server | =2012-4 | |
Microsoft Team Foundation Server | =2013-5 | |
Microsoft Team Foundation Server | =2015-4.2 | |
Microsoft Team Foundation Server | =2017-3.1 | |
Microsoft Team Foundation Server | =2018-1.2 | |
Microsoft Team Foundation Server | =2018-3.2 | |
Microsoft Azure DevOps Server | =2019.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-1072 is a remote code execution vulnerability that exists when Azure DevOps Server and Team Foundation Server (TFS) improperly handle user input.
CVE-2019-1072 affects Microsoft Team Foundation Server versions 2010-SP1, 2012-4, 2013-5, 2015-4.2, 2017-3.1, 2018-1.2, and 2018-3.2.
CVE-2019-1072 affects Microsoft Azure DevOps Server 2019.0.1.
CVE-2019-1072 has a severity rating of 9.8, which is considered critical.
To mitigate the risk of CVE-2019-1072, it is recommended to apply the security updates provided by Microsoft.