Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2018-8529

Опубликовано: 13 нояб. 2018
Источник: msrc
EPSS Средний

Описание

Team Foundation Server Remote Code Execution Vulnerability

A remote code execution vulnerability exists when Team Foundation Server (TFS) does not enable basic authorization on the communication between the TFS and Search services. Without basic authorization, an attacker could run certain commands on the Search service.

The security update addresses the vulnerability by ensuring that Team Foundation Server enables basic authorization.

Обновления

ПродуктСтатьяОбновление
Team Foundation Server 2018 Update 1.1
Team Foundation Server 2018 Update 3

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

DOS

N/A

EPSS

Процентиль: 97%
0.35738
Средний

Связанные уязвимости

CVSS3: 9.8
nvd
около 7 лет назад

A remote code execution vulnerability exists when Team Foundation Server (TFS) does not enable basic authorization on the communication between the TFS and Search services, aka "Team Foundation Server Remote Code Execution Vulnerability." This affects Team.

CVSS3: 9.8
github
больше 3 лет назад

A remote code execution vulnerability exists when Team Foundation Server (TFS) does not enable basic authorization on the communication between the TFS and Search services, aka "Team Foundation Server Remote Code Execution Vulnerability." This affects Team.

CVSS3: 6.3
fstec
около 7 лет назад

Уязвимость программного средства Microsoft Team Foundation Server, связанная с ошибками процедуры авторизации, позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 97%
0.35738
Средний