CVE-2018-8529

CRITICAL

Microsoft Team Foundation Server - Search Service Remote Code Execution

Title source: manual
STIX 2.1

Description

A remote code execution vulnerability exists when Team Foundation Server (TFS) does not enable basic authorization on the communication between the TFS and Search services, aka "Team Foundation Server Remote Code Execution Vulnerability." This affects Team.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/105910

Scores

CVSS v3 9.8
EPSS 0.1346
EPSS Percentile 96.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (1)
microsoft/team_foundation_server 2018 1.1 (2 CPE variants)
Published Nov 15, 2018
Tracked Since Feb 18, 2026