CVE-2018-8529
critical · 9.8A remote code execution vulnerability exists when Team Foundation Server (TFS) does not enable basic authorization on the communication between the TFS and Search services, aka "Team Foundation Server Remote Code Execution Vulnerability." This affects Team.
9.8
CVSS
13.5%
EPSS (exploit prob.)
96th
EPSS percentile
2018-11-15
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | team_foundation_server | 2018 |
| microsoft | team_foundation_server | 2018 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2018-8529