CVE-2022-35805CriticalCVSS 8.8
Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
How could an attacker exploit this vulnerability? An authenticated user could run a specially crafted trusted solution package to execute arbitrary SQL commands. From there the attacker could escalate and execute commands as db_owner within their Dynamics CRM database.
According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? The attacker must be authenticated to be able to exploit this vulnerability.
🎯 Affected products2
- Microsoft Dynamics CRM (on-premises) 9.0
- Microsoft Dynamics CRM (on-premises) 9.1
✅ Remediation
KB5017524 (Security Update) — fixed build 9.0.40.5 KB5017226 (Security Update) — fixed build 9.1.12.17