CVE-2019-1306
A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to validate input properly, aka 'Azure DevOps and Team Foundation Server Remote Code Execution Vulnerability'.
- Affected products
- Azure Devops Server, Team Foundation Server
- Microsoft Team Foundation Server
- = 2018
- Microsoft Azure Devops Server
- = 2019, 2019.0.1
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 17.0% (97th percentile)
- Weakness
- CWE-20
- NVD status
- Modified
- Published
- 2019-09-11
CVE-2019-1306 at NVD
1 known exploit for CVE-2019-1306
Proof-of-concept code and exploit modules indexed by Sploitus