CVE-2023-36437HighCVSS 8.8

Azure DevOps Server Remote Code Execution Vulnerability

Published
November 14, 2023
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

How could an attacker exploit this vulnerability? An attacker could exploit an integer overflow vulnerability that results in arbitrary heap writes, which could be used to perform arbitrary code execution.

According to the CVSS metric, privileges required is low (PR:L). Does the attacker need to be in an authenticated role on ADO? Yes, the attacker needs to be authenticated to Azure DevOps server.

🎯 Affected products1

  • Azure Pipelines Agent

✅ Remediation

KBPull Request (Security Update) — fixed build 2.39.1

🔗 References (2)