CVE-2021-42316CriticalCVSS 8.8

Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability

Published
November 9, 2021
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

What privileges could an attacker gain with successful exploitation of this vulnerability? An attacker can write to any file where the webserver user (nt authority\network service) has write access.

🎯 Affected products2

  • Microsoft Dynamics 365 (on-premises) version 9.0
  • Microsoft Dynamics 365 (on-premises) version 9.1

✅ Remediation

KB5008478 (Security Update) — fixed build 9.1.6.3 KB5008479 (Security Update) — fixed build 9.0.34.5

🔗 References (5)