CVE-2019-1072
critical · 9.8A remote code execution vulnerability exists when Azure DevOps Server and Team Foundation Server (TFS) improperly handle user input, aka 'Azure DevOps Server and Team Foundation Server Remote Code Execution Vulnerability'.
9.8
CVSS
12.4%
EPSS (exploit prob.)
96th
EPSS percentile
2019-07-15
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-20
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | team_foundation_server | 2010 |
| microsoft | team_foundation_server | 2012 |
| microsoft | team_foundation_server | 2013 |
| microsoft | team_foundation_server | 2015 |
| microsoft | team_foundation_server | 2017 |
| microsoft | team_foundation_server | 2018 |
| microsoft | team_foundation_server | 2018 |
| microsoft | azure_devops_server | 2019.0.1 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2019-1072