CVE-2018-8654Critical

Microsoft Dynamics 365 Elevation of Privilege Vulnerability

Published
February 13, 2019
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

An elevation of privilege vulnerability exists in Microsoft Dynamics 365 Server. An attacker who successfully exploited this vulnerability could attempt to impersonate any other user of the Dynamics server. To exploit the vulnerability, an authenticated attacker would need to send a specially crafted request to an affected server, thereby allowing impersonation of another Dynamics CRM user. The security update addresses the vulnerability by correcting how Microsoft Dynamics 365 Server validates and sanitizes user input.

🎯 Affected products1

  • Microsoft Dynamics 365 (on-premises) version 8

✅ Remediation

KB4467675 (Security Update)

🔗 References (2)