CVE-2022-23274HighCVSS 8.8

Microsoft Dynamics GP Remote Code Execution Vulnerability

Published
February 8, 2022
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

How could an attacker exploit this vulnerability? An authenticated user could send a specially crafted SQL request to a Dynamics GP Web Service and perform remote code execution.

According to the CVSS metric, successful exploitation of this vulnerability could lead to total loss of availability (A:H)? What does that mean for this vulnerability? An attacker could impact availability of the data by assuming control of the server through remote code execution.

🎯 Affected products1

  • Microsoft Dynamics GP

✅ Remediation

KBRelease Notes (Security Update) — fixed build 18.4.1434

🔗 References (2)