#VU35497 Input validation error in Team Foundation Server and Azure DevOps Server - CVE-2019-1306
Published: September 12, 2019 / Updated: August 8, 2020
Team Foundation Server
Azure DevOps Server
Microsoft
Description
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to validate input properly, aka 'Azure DevOps and Team Foundation Server Remote Code Execution Vulnerability'.