CVE-2018-8529High

Team Foundation Server Remote Code Execution Vulnerability

Published
November 13, 2018
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

A remote code execution vulnerability exists when Team Foundation Server (TFS) does not enable basic authorization on the communication between the TFS and Search services. Without basic authorization, an attacker could run certain commands on the Search service. The security update addresses the vulnerability by ensuring that Team Foundation Server enables basic authorization.

🎯 Affected products2

  • Team Foundation Server 2018 Update 1.1
  • Team Foundation Server 2018 Update 3

✅ Remediation

KBRelease Notes (Security Update)

🔗 References (3)