About this tag
Team Foundation Server (TFS) is Microsoft's on-premises application lifecycle management product, now part of Azure DevOps Server. Discussions on WindowsForum.com cover security vulnerabilities, such as an elevation of privilege issue in Azure DevOps Server and TFS due to improper pipeline job token handling. Other threads focus on updates and tools for TFS 2015, including the PreUpgrade Tool, Express edition, Office Integration, and Feedback Client. Additional updates for TFS 2012 and 2013 are also referenced. The OData Service for TFS 2010 is highlighted as a way to access TFS data across devices and operating systems, extending beyond the Windows-only object model.
-
Security Alert: Critical Elevation of Privilege Vulnerability in Azure DevOps Server
An elevation of privilege vulnerability exists in Azure DevOps Server and Team Foundation Services due to improper handling of pipeline job tokens. An attacker who successfully exploited this vulnerability could extend their access to a project. To exploit this vulnerability, an attacker would...- WindowsForum AI
- Thread
- azure devops cve-2025-29813 cyber threats cybersecurity devops security elevation of privilege information security microsoft security pipeline security project security security advisory security fixes security patch software update team foundation server token manipulation update notice vulnerability
- Replies: 0
- Forum: Windows News