CVE-2019-1072

Severity
9.8CRITICAL
EPSS
24.1%
top 3.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 15
Latest updateMay 24

Description

A remote code execution vulnerability exists when Azure DevOps Server and Team Foundation Server (TFS) improperly handle user input, aka 'Azure DevOps Server and Team Foundation Server Remote Code Execution Vulnerability'.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages9 packages

CVEListV5microsoft/azure_devops_server2019.0.1
CVEListV5microsoft/team_foundation_server2017 Update 3.1
CVEListV5microsoft/team_foundation_server_2010SP1 (x64), SP1 (x86)+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-g5c6-v9ph-hmxh: A remote code execution vulnerability exists when Azure DevOps Server and Team Foundation Server (TFS) improperly handle user input, aka 'Azure DevOps2022-05-24
CVEList
CVE-2019-1072: A remote code execution vulnerability exists when Azure DevOps Server and Team Foundation Server (TFS) improperly handle user input, aka 'Azure DevOps2019-07-15

📋Vendor Advisories

1
Microsoft
Azure DevOps Server and Team Foundation Server Remote Code Execution Vulnerability2019-07-09
CVE-2019-1072 (CRITICAL CVSS 9.8) | A remote code execution vulnerabili | cvebase.io