CVE-2024-20667

EUVD-2024-18382
Azure DevOps Server Remote Code Execution Vulnerability
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
microsoftCNA
7.5 HIGH
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 69.79%
Affected Products (NVD)
VendorProductVersion
microsoftazure_devops_server
2019.1.2
microsoftazure_devops_server
2020.1.2
microsoftazure_devops_server
2022.1
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
microsoftazure_devops
1.0.0 ≤
𝑥
< 20240126.6
CNA
microsoftazure_devops
2020.1.0 ≤
𝑥
< 20240126.2
CNA
microsoftazure_devops
20231128.1 ≤
𝑥
< 20240126.4
CNA