Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2024-20667: Azure DevOps Server Remote Code Execution Vulnerability

According to the CVSS metric, the attack vector is network (AV:N), attack complexity is high (AC:H), and privilege required is low (PR:L). What is the target used in the context of the remote code execution?

Successful exploitation of this vulnerability requires the attacker to have Queue Build permissions and for the target Azure DevOps pipeline to meet certain conditions for an attacker to exploit this vulnerability.

Microsoft Security Response Center
#vulnerability#rce#Azure DevOps#Security Vulnerability

Microsoft Security Response Center: Latest News

CVE-2024-11395: Chromium: CVE-2024-11395 Type Confusion in V8