← All CVEs

CVE-2018-8529

critical · 9.8

A remote code execution vulnerability exists when Team Foundation Server (TFS) does not enable basic authorization on the communication between the TFS and Search services, aka "Team Foundation Server Remote Code Execution Vulnerability." This affects Team.

9.8
CVSS
13.5%
EPSS (exploit prob.)
96th
EPSS percentile
2018-11-15
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

VendorProductAffected versions
microsoftteam_foundation_server2018
microsoftteam_foundation_server2018

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-8529