Vulnerabilities > Microsoft > Team Foundation Server > Critical

DATE CVE VULNERABILITY TITLE RISK
2019-09-11 CVE-2019-1306 Improper Input Validation vulnerability in Microsoft Azure Devops Server and Team Foundation Server
A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to validate input properly, aka 'Azure DevOps and Team Foundation Server Remote Code Execution Vulnerability'.
network
low complexity
microsoft CWE-20
critical
9.8
2019-07-15 CVE-2019-1072 Improper Input Validation vulnerability in Microsoft Azure Devops Server and Team Foundation Server
A remote code execution vulnerability exists when Azure DevOps Server and Team Foundation Server (TFS) improperly handle user input, aka 'Azure DevOps Server and Team Foundation Server Remote Code Execution Vulnerability'.
network
low complexity
microsoft CWE-20
critical
9.8
2018-11-15 CVE-2018-8529 Unspecified vulnerability in Microsoft Team Foundation Server 2018
A remote code execution vulnerability exists when Team Foundation Server (TFS) does not enable basic authorization on the communication between the TFS and Search services, aka "Team Foundation Server Remote Code Execution Vulnerability." This affects Team.
network
low complexity
microsoft
critical
9.8