CVE-2020-1022Critical

Dynamics Business Central Remote Code Execution Vulnerability

Published
April 14, 2020
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

A remote code execution vulnerability exists in Microsoft Dynamics Business Central. An attacker who successfully exploited this vulnerability could execute arbitrary shell commands on victim's server. To exploit the vulnerability, an authenticated attacker needs to convince the victim into connect to a malicious Dynamics Business Central client or elevate permission to system to perform the code execution. The security update addresses the vulnerability by preventing the possibility of using a binary type that could eventually execute code on the victim’s server.

🎯 Affected products8

  • Dynamics 365 Business Central 2019 Release Wave 2 (On-Premise)
  • Dynamics 365 Business Central 2019 Spring Update
  • Microsoft Dynamics 365 BC On Premise
  • Microsoft Dynamics NAV 2013
  • Microsoft Dynamics NAV 2015
  • Microsoft Dynamics NAV 2016
  • Microsoft Dynamics NAV 2017
  • Microsoft Dynamics NAV 2018

✅ Remediation

KB4557700 (Security Update) KB4549676 (Security Update) KB4549675 (Security Update) KB4557699 (Security Update) KB4549673 (Security Update) KB4549674 (Security Update) KB4549678 (Security Update) KB4549677 (Security Update)

🔗 References (9)