CVE-2020-1018High
Microsoft Dynamics Business Central/NAV Information Disclosure
🔗 CVE IDs covered (1)
📋 Description
An information disclosure vulnerability exists when Microsoft Dynamics Business Central/NAV on-premise does not properly hide the value of a masked field when showing the records as a chart page. The attacker who successfully exploited the vulnerability could see the information that are in a masked field. The security update addresses the vulnerability by updating the rendering engine the Windows client to properly detect masked fields and render the content as masked.
🎯 Affected products6
- Dynamics 365 Business Central 2019 Spring Update
- Microsoft Dynamics 365 BC On Premise
- Microsoft Dynamics NAV 2015
- Microsoft Dynamics NAV 2016
- Microsoft Dynamics NAV 2017
- Microsoft Dynamics NAV 2018
✅ Remediation
KB4549673 (Security Update) KB4549674 (Security Update) KB4549675 (Security Update) KB4557700 (Security Update) KB4549676 (Security Update) KB4549677 (Security Update)
🔗 References (7)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-1018
- patchhttps://www.microsoft.com/en-us/download/details.aspx?id=101066
- patchhttps://www.microsoft.com/en-us/download/details.aspx?id=101068
- patchhttps://www.microsoft.com/en-us/download/details.aspx?id=101067
- patchhttps://www.microsoft.com/en-us/download/details.aspx?id=101089
- patchhttps://www.microsoft.com/en-us/download/details.aspx?id=101071
- patchhttps://www.microsoft.com/en-us/download/details.aspx?id=101069