VDB

CVE-2019-1072

CVE-2019-1072 PUBLISHED CVSS 7.5 HIGH

A remote code execution vulnerability exists when Azure DevOps Server and Team Foundation Server (TFS) improperly handle user input, aka 'Azure DevOps Server and Team Foundation Server Remote Code Execution Vulnerability'.

EPSS 24.11% · 96.2th percentile

Risk Scores

CVSS 2.0
7.5
EPSS Score
24.11%
96.2th percentile

Affected Products

VendorProductVersions
MicrosoftTeam Foundation Server 2013 Update 5unspecified
MicrosoftTeam Foundation Server 2015Update 4.2
microsoftteam_foundation_server2017, 2018, 2018
MicrosoftTeam Foundation Server 2018Update 3.2, Update 1.2
MicrosoftTeam Foundation Server 2012Update 4
MicrosoftTeam Foundation Server 2010SP1 (x64), SP1 (x86)
MicrosoftAzure DevOps Server2019.0.1
microsoftazure_devops_server2019.0.1
MicrosoftTeam Foundation Server2017 Update 3.1

Timeline

  • Jul 10, 2019 CVE Published
  • Apr 14, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Mar 8, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
  • Jan 9, 2023 EPSS Score
  • Mar 11, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›