CVE-2019-1072 PUBLISHED CVSS 7.5 HIGH

A remote code execution vulnerability exists when Azure DevOps Server and Team Foundation Server (TFS) improperly handle user input, aka 'Azure DevOps Server and Team Foundation Server Remote Code Execution Vulnerability'.

EPSS 24.11% · 96.0th percentile

Risk Scores

CVSS v2.0
7.5
EPSS Score
24.11%
96.0th percentile

Affected Products

VendorProductVersions
MicrosoftTeam Foundation Server 2013 Update 5unspecified
MicrosoftTeam Foundation Server 2015Update 4.2
microsoftteam_foundation_server2018, 2013, 2017
MicrosoftTeam Foundation Server 2018Update 3.2, Update 1.2
MicrosoftTeam Foundation Server 2012Update 4
MicrosoftTeam Foundation Server 2010SP1 (x64), SP1 (x86)
MicrosoftAzure DevOps Server2019.0.1
microsoftazure_devops_server2019.0.1
MicrosoftTeam Foundation Server2017 Update 3.1

Timeline

References

Open in Interactive Console →