CVE-2019-1306

Severity
9.8CRITICAL
EPSS
26.0%
top 3.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 11
Latest updateMay 24

Description

A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to validate input properly, aka 'Azure DevOps and Team Foundation Server Remote Code Execution Vulnerability'.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages5 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-wvw6-4r49-h4g6: A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to validate input properly, aka 'Azu2022-05-24
CVEList
CVE-2019-1306: A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to validate input properly, aka 'Azu2019-09-11

📋Vendor Advisories

1
Microsoft
Azure DevOps and Team Foundation Server Remote Code Execution Vulnerability2019-09-10

🕵️Threat Intelligence

2
Trendmicro
CVE-2019-1306: Are you my Index?2019-10-24
Trendmicro
CVE-2019-1306: Are you my Index?2019-10-24
CVE-2019-1306 (CRITICAL CVSS 9.8) | A remote code execution vulnerabili | cvebase.io