Back

CVE-2018-8529

CRITICAL

A remote code execution vulnerability exists when Team Foundation Server (TFS) does not enable basic authorization on the communication between the TFS and Search services, aka "Team Foundation Server Remote Code Execution Vulnerability." This affects Team.

Published: Nov 15, 2018 Modified: Jun 17, 2026
NVD-CWE-noinfo

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (2)

Vendor Product Version
microsoft team_foundation_server 2018
microsoft team_foundation_server 2018

GitHub Security Advisory GHSA-g635-3cv2-g7jq

A remote code execution vulnerability exists when Team Foundation Server (TFS) does not enable...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 13.46%

Top 4% most likely to be exploited

Threat Score 43.2 / 100

Data Sources

NVD EPSS GitHub