CVE-2023-36437HighCVSS 8.8
Azure DevOps Server Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
How could an attacker exploit this vulnerability? An attacker could exploit an integer overflow vulnerability that results in arbitrary heap writes, which could be used to perform arbitrary code execution.
According to the CVSS metric, privileges required is low (PR:L). Does the attacker need to be in an authenticated role on ADO? Yes, the attacker needs to be authenticated to Azure DevOps server.
🎯 Affected products1
- Azure Pipelines Agent
✅ Remediation
KBPull Request (Security Update) — fixed build 2.39.1