CVE-2022-23259CriticalCVSS 8.8

Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability

Published
April 12, 2022
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

How could an attacker exploit this vulnerability? An authenticated user could run a specially crafted trusted solution package to execute arbitrary SQL commands. From there the attacker could escalate and execute commands as db_owner within their Dynamics CRM database.

🎯 Affected products2

  • Microsoft Dynamics 365 (on-premises) version 9.0
  • Microsoft Dynamics 365 (on-premises) version 9.1

✅ Remediation

KB5012732 (Security Update) — fixed build 9.0.37.2 KB5012731 (Security Update) — fixed build 9.1.9.8

🔗 References (5)