← All CVEs

CVE-2019-1072

critical · 9.8

A remote code execution vulnerability exists when Azure DevOps Server and Team Foundation Server (TFS) improperly handle user input, aka 'Azure DevOps Server and Team Foundation Server Remote Code Execution Vulnerability'.

9.8
CVSS
12.4%
EPSS (exploit prob.)
96th
EPSS percentile
2019-07-15
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
microsoftteam_foundation_server2010
microsoftteam_foundation_server2012
microsoftteam_foundation_server2013
microsoftteam_foundation_server2015
microsoftteam_foundation_server2017
microsoftteam_foundation_server2018
microsoftteam_foundation_server2018
microsoftazure_devops_server2019.0.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-1072