CVE-2018-8529
Summary
| CVE | CVE-2018-8529 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-11-15 19:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | A remote code execution vulnerability exists when Team Foundation Server (TFS) does not enable basic authorization on the communication between the TFS and Search services, aka "Team Foundation Server Remote Code Execution Vulnerability." This affects Team. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Team Foundation Server | 2018 | 1.1 | All | All |
| Application | Microsoft | Team Foundation Server | 2018 | 3 | All | All |
| Application | Microsoft | Team Foundation Server | 2018 | 1.1 | All | All |
| Application | Microsoft | Team Foundation Server | 2018 | 3 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8529 | CONFIRM | portal.msrc.microsoft.com | Patch, Vendor Advisory |
| Microsoft Team Foundation Server CVE-2018-8529 Remote Code Execution Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.