CVE-2019-1072 — Azure DevOps Server and Team Foundation Server Remote Code Execution Vulnerability
Executive Summary
A remote code execution vulnerability exists when Azure DevOps Server and Team Foundation Server (TFS) improperly handle user input. An attacker who successfully exploited the vulnerability could execute code on the target server in the context of the DevOps or TFS service account. To exploit the vulnerability, an attacker could submit a specially crafted file to an affected server. If anonymous access is allowed to projects on an affected server, the attacker would not require authentication. The update corrects the way that DevOps Server and TFS process certain file types.
Overview
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Azure DevOps Server 2019.0.1 | Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) |
Critical | Remote Code Execution | Maybe |
| Team Foundation Server 2010 SP1 (x64) | Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) |
Critical | Remote Code Execution | Maybe |
| Team Foundation Server 2010 SP1 (x86) | Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) |
Critical | Remote Code Execution | Maybe |
| Team Foundation Server 2012 Update 4 | Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) |
Critical | Remote Code Execution | Maybe |
| Team Foundation Server 2013 Update 5 | Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) |
Critical | Remote Code Execution | Maybe |
| Team Foundation Server 2015 Update 4.2 | Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) |
Critical | Remote Code Execution | Maybe |
| Team Foundation Server 2017 Update 3.1 | Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) |
Critical | Remote Code Execution | Maybe |
| Team Foundation Server 2018 Update 1.2 | Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) |
Critical | Remote Code Execution | Maybe |
| Team Foundation Server 2018 Update 3.2 | Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) |
Critical | Remote Code Execution | Maybe |
Patches
| Article | Type | Restart |
|---|---|---|
Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes (Security Update) Release Notes |
Security Update | Maybe |
Known Exploits
Acknowledgments
Microsoft has not published researcher acknowledgments for this CVE, or they are not yet reflected in our data source. Check the MSRC advisory directly for the most current credit information.