CVE-2022-23259CriticalCVSS 8.8
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
How could an attacker exploit this vulnerability? An authenticated user could run a specially crafted trusted solution package to execute arbitrary SQL commands. From there the attacker could escalate and execute commands as db_owner within their Dynamics CRM database.
🎯 Affected products2
- Microsoft Dynamics 365 (on-premises) version 9.0
- Microsoft Dynamics 365 (on-premises) version 9.1
✅ Remediation
KB5012732 (Security Update) — fixed build 9.0.37.2 KB5012731 (Security Update) — fixed build 9.1.9.8
🔗 References (5)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-23259
- patchhttps://www.microsoft.com/en-us/download/details.aspx?id=104010
- referencehttps://support.microsoft.com/help/5012732
- patchhttps://www.microsoft.com/en-us/download/details.aspx?id=104009
- referencehttps://support.microsoft.com/help/5012731