CVE-2023-38155
published 2023-09-12CVE-2023-38155: Azure DevOps Server Remote Code Execution Vulnerability
PriorityP350high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
1.29%
66.8th percentile
Azure DevOps Server Remote Code Execution Vulnerability
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | azure_devops_server | — | — |
| microsoft | azure_devops_server | — | — |
| microsoft | azure_devops_server | — | — |
| microsoft | azure_devops_server | — | — |
| microsoft | azure_devops_server | — | — |
| microsoft | azure_devops_server | >= 1.0.0 < 20230825.1 | 20230825.1 |
| microsoft | azure_devops_server_2019.0.1 | >= 2019.0.0 < 20230601.3 | 20230601.3 |
| microsoft | azure_devops_server_2020.0.2 | >= 2020.0.0 < 20230820.2 | 20230820.2 |
| microsoft | azure_devops_server_2020.1.2 | >= 2020.1.0 < 20230823.1 | 20230823.1 |
| microsoft | azure_devops_server_2022.0.1 | >= 2022.0.0 < 20230825.4 | 20230825.4 |
| msrc | azure_devops_server_2019.0.1 | — | — |
| msrc | azure_devops_server_2019.1.2 | — | — |
| msrc | azure_devops_server_2020.0.2 | — | — |
| msrc | azure_devops_server_2020.1.2 | — | — |
| msrc | azure_devops_server_2022.0.1 | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_msrc7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jw6j-8p3q-xrff: Azure DevOps Server and Team Foundation Server Elevation of Privilege Vulnerability
ghsa_unreviewed·2023-09-12
CVE-2023-38155 [HIGH] GHSA-jw6j-8p3q-xrff: Azure DevOps Server and Team Foundation Server Elevation of Privilege Vulnerability
Azure DevOps Server and Team Foundation Server Elevation of Privilege Vulnerability
Microsoft
Azure DevOps Server Remote Code Execution Vulnerability
vendor_msrc·2023-09-12·CVSS 7.0
CVE-2023-38155 [HIGH] CWE-502 Azure DevOps Server Remote Code Execution Vulnerability
Azure DevOps Server Remote Code Execution Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited the vulnerability?
An attacker who successfully exploited this vulnerability could gain administrator privileges.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to gather information specific to the environment and take additional actions prior to exploitation to prepare the target environment.
Azure DevOps: Azure DevOps
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely
Remediation: Re
No detection rules found.
No public exploits indexed.
2023-09-12
Published