← All CVEs

CVE-2019-1306

critical · 9.8

A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to validate input properly, aka 'Azure DevOps and Team Foundation Server Remote Code Execution Vulnerability'.

9.8
CVSS
17.0%
EPSS (exploit prob.)
97th
EPSS percentile
2019-09-11
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
microsoftteam_foundation_server2018
microsoftazure_devops_server2019
microsoftazure_devops_server2019.0.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-1306