CVE Database
/

CVE-2019-1072

Back to search

CVE-2019-1072

Published: Jul 15, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

A remote code execution vulnerability exists when Azure DevOps Server and Team Foundation Server (TFS) improperly handle user input, aka 'Azure DevOps Server and Team Foundation Server Remote Code Execution Vulnerability'.

VendorProductVersions

Microsoft

Team Foundation Server 2012

affected
Update 4

Microsoft

Team Foundation Server 2013 Update 5

affected
unspecified

Microsoft

Team Foundation Server 2018

affected
Update 1.2
affected
Update 3.2

Microsoft

Team Foundation Server

affected
2017 Update 3.1

Microsoft

Team Foundation Server 2015

affected
Update 4.2

Microsoft

Azure DevOps Server

affected
2019.0.1

Microsoft

Team Foundation Server 2010

affected
SP1 (x86)
affected
SP1 (x64)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now