Deserialization of Untrusted Data in Azure DevOps Server - CVE-2023-38155
Published: September 12, 2023 / Updated: September 14, 2023
Azure DevOps Server
Microsoft
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to insecure input validation when processing serialized data within the MachinePropertyBag class. A local user can pass specially crafted data to the server and execute arbitrary code with elevated privileges.