CVE-2023-36561 is an Elevation of Privilege vulnerability affecting Azure DevOps Server. This vulnerability has a CVSS score of 7.3 (HIGH), indicating it can be exploited remotely with low attack complexity, potentially leading to low impact on confidentiality, integrity, and availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available and it is not listed in the KEV catalog, it has received some community discussion and media coverage, including mention in Microsoft's October 2023 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2020.0.2CPE matchmatch criteria | cpe:2.3:o:microsoft:azure_devops_server:2020.0.2:-:*:*:*:*:*:* | ||
2020.1.2CPE matchmatch criteria | cpe:2.3:o:microsoft:azure_devops_server:2020.1.2:-:*:*:*:*:*:* | ||
2022.0.1CPE matchmatch criteria | cpe:2.3:o:microsoft:azure_devops_server:2022.0.1:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.