CVE-2023-33136
published 2023-09-12CVE-2023-33136: Azure DevOps Server Remote Code Execution Vulnerability
PriorityP359high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.74%
75.1th percentile
Azure DevOps Server Remote Code Execution Vulnerability
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | azure_devops_server | — | — |
| microsoft | azure_devops_server | — | — |
| microsoft | azure_devops_server | — | — |
| microsoft | azure_devops_server | — | — |
| microsoft | azure_devops_server | — | — |
| microsoft | azure_devops_server | >= 1.0.0 < 20230825.1 | 20230825.1 |
| microsoft | azure_devops_server_2019.0.1 | >= 2019.0.0 < 20230601.3 | 20230601.3 |
| microsoft | azure_devops_server_2020.0.2 | >= 2020.0.0 < 20230820.2 | 20230820.2 |
| microsoft | azure_devops_server_2020.1.2 | >= 2020.1.0 < 20230823.1 | 20230823.1 |
| microsoft | azure_devops_server_2022.0.1 | >= 2022.0.0 < 20230825.4 | 20230825.4 |
| msrc | azure_devops_server_2019.0.1 | — | — |
| msrc | azure_devops_server_2019.1.2 | — | — |
| msrc | azure_devops_server_2020.0.2 | — | — |
| msrc | azure_devops_server_2020.1.2 | — | — |
| msrc | azure_devops_server_2022.0.1 | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Azure DevOps Server Remote Code Execution Vulnerability
vendor_msrc·2023-09-12·CVSS 8.8
CVE-2023-33136 [HIGH] CWE-77 Azure DevOps Server Remote Code Execution Vulnerability
Azure DevOps Server Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, the attack vector is network (AV:N), attack complexity is low (AC:L), and privilege required is low (PR:L). What is the target used in the context of the remote code execution?
Successful exploitation of this vulnerability requires an attacker to have Queue Build permissions on an Azure DevOps pipeline that has an overridable variable. An attacker with these permissions could perform remote code execution (RCE) by performing a malicious input injection via a runtime parameter that could be used in place of the overridable variable.
Azure DevOps: Azure DevOps
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest
GHSA
GHSA-rw46-pqg7-qwfj: Azure DevOps Server Remote Code Execution Vulnerability
ghsa_unreviewed·2023-09-12
CVE-2023-33136 [HIGH] GHSA-rw46-pqg7-qwfj: Azure DevOps Server Remote Code Execution Vulnerability
Azure DevOps Server Remote Code Execution Vulnerability
No detection rules found.
No public exploits indexed.
2023-09-12
Published