CVE-2021-34474CriticalCVSS 8.0
Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). Can the exploit move from Dynamics Business Central to the underlying operating system? An attacker who successfully exploited this vulnerability could use it to pivot from the machine to the rest of the network.
🎯 Affected products3
- Microsoft Dynamics 365 Business Central 2020 Release Wave 1 - Update 16.14
- Microsoft Dynamics 365 Business Central 2020 Release Wave 2 - Update 17.8
- Microsoft Dynamics 365 Business Central 2021 Release Wave 1 - Update 18.3
✅ Remediation
KB5004717 (Security Update) — fixed build 16.0.27253 KB5004716 (Security Update) — fixed build 17.0.27235 KB5004715 (Security Update) — fixed build 18.0.27469
🔗 References (7)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34474
- patchhttps://www.microsoft.com/en-us/download/details.aspx?id=103251
- referencehttps://support.microsoft.com/en-us/help/5004717
- patchhttps://www.microsoft.com/en-us/download/details.aspx?id=103249
- referencehttps://support.microsoft.com/en-us/help/5004716
- patchhttps://www.microsoft.com/en-us/download/details.aspx?id=103250
- referencehttps://support.microsoft.com/en-us/help/5004715