CVE-2022-41066HighCVSS 4.4

Microsoft Dynamics Business Central Information Disclosure Vulnerability

Published
November 8, 2022
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to gather information specific to the environment of the targeted component.

According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to take additional actions prior to exploitation to prepare the target environment.

According to the CVSS metric, privileges required is high (PR:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to compromise admin credentials on the device.

What type of information could be disclosed by this vulnerability? An attacker who successfully exploited this vulnerability could use it to view integration secrets that are owned by a different partner.

🎯 Affected products5

  • Dynamics 365 Business Central Spring 2019 Update
  • Microsoft Dynamics 365 Business Central 2021 Release Wave 2
  • Microsoft Dynamics 365 Business Central 2022 Release Wave 1
  • Microsoft Dynamics 365 Business Central 2022 Release Wave 2
  • Microsoft Dynamics NAV 2018

✅ Remediation

KB5021000 (Security Update) — fixed build 49345 KB5021001 (Security Update) — fixed build 14.0.49339 KB5021004 (Security Update) — fixed build 21.0.48504 KB5021002 (Security Update) — fixed build 20.0.48457 KB5021003 (Security Update) — fixed build 19.0.48446

🔗 References (11)