CVE-2022-35805CriticalCVSS 8.8

Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability

Published
September 13, 2022
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

How could an attacker exploit this vulnerability? An authenticated user could run a specially crafted trusted solution package to execute arbitrary SQL commands. From there the attacker could escalate and execute commands as db_owner within their Dynamics CRM database.

According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? The attacker must be authenticated to be able to exploit this vulnerability.

🎯 Affected products2

  • Microsoft Dynamics CRM (on-premises) 9.0
  • Microsoft Dynamics CRM (on-premises) 9.1

✅ Remediation

KB5017524 (Security Update) — fixed build 9.0.40.5 KB5017226 (Security Update) — fixed build 9.1.12.17

🔗 References (4)