Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). Can the exploit move from Dynamics NAV to the underlying operating system? Yes. An attacker who successfully exploited this vulnerability in Dynamics NAV could execute code on the host server in the context of the service account Dynamics has been configured to use.
According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? The attacker must be authenticated to be able to exploit this vulnerability.
According to the CVSS metric, the attack vector is network (AV:N). What is the target used in the context of the remote code execution? The Dynamics NAV opened port could be used to connect with the WCF TCP protocol. As an authenticated user, the attacker could attempt to trigger malicious code in the context of the server's account through a network call.
According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to prepare the target environment to improve exploit reliability.
🎯 Affected products13
- Dynamics 365 Business Central 2019 Release Wave 2 (On-Premise)
- Dynamics 365 Business Central Spring 2019 Update
- Microsoft Dynamics 365 Business Central 2020 Release Wave 1
- Microsoft Dynamics 365 Business Central 2020 Release Wave 2
- Microsoft Dynamics 365 Business Central 2021 Release Wave 1
- Microsoft Dynamics 365 Business Central 2021 Release Wave 2
- Microsoft Dynamics 365 Business Central 2022 Release Wave 1
- Microsoft Dynamics 365 Business Central 2022 Release Wave 2
- Microsoft Dynamics NAV 2013 R2
- Microsoft Dynamics NAV 2015
- Microsoft Dynamics NAV 2016
- Microsoft Dynamics NAV 2017
- Microsoft Dynamics NAV 2018
✅ Remediation
KB5005293 (Security Update) — fixed build Build 52203 KB5010202 (Security Update) — fixed build Build 30712 KB5021668 (Security Update) — fixed build Build 49497 KBRelease Notes (Security Update) — fixed build 52204 KB5021669 (Security Update) — fixed build 14.0.49494 KB5001733 (Security Update) — fixed build 15.0.48426 KB5013420 (Security Update) — fixed build 17.0.38061 KB5010910 (Security Update) — fixed build 16.0.35120 KB5021671 (Security Update) — fixed build 20.0.49947 KB5021670 (Security Update) — fixed build 19.0.49925 KB5021672 (Security Update) — fixed build 21.0.49984 KB5019239 (Security Update) — fixed build 18.0.46905 KBRelease Notes (Security Update) — fixed build 52297
🔗 References (26)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41127
- patchhttps://download.microsoft.com/download/9/c/b/9cb2a25f-255f-41d2-a677-5261098a7362/W1DVD.zip
- referencehttps://support.microsoft.com/en-us/help/5005293
- patchhttps://download.microsoft.com/download/e/a/2/ea2c9509-3f7b-43a2-b64d-cbaf0ece9926/W1DVD.zip
- referencehttps://support.microsoft.com/en-us/help/5010202
- patchhttps://www.microsoft.com/en-us/download/details.aspx?id=104806
- referencehttps://support.microsoft.com/en-us/help/5021668
- referencehttps://Released Cumulative Updates for Microsoft Dynamics NAV 2015 - Microsoft Support
- patchhttps://www.microsoft.com/en-us/download/details.aspx?id=104803
- referencehttps://support.microsoft.com/en-us/help/5021669
- patchhttps://www.microsoft.com/en-us/download/details.aspx?id=104808
- referencehttps://support.microsoft.com/en-us/help/5001733
- patchhttps://www.microsoft.com/en-us/download/details.aspx?id=104810
- referencehttps://support.microsoft.com/en-us/help/5013420
- patchhttps://www.microsoft.com/en-us/download/details.aspx?id=104809
- referencehttps://support.microsoft.com/en-us/help/5010910
- patchhttps://www.microsoft.com/en-us/download/details.aspx?id=104807
- referencehttps://support.microsoft.com/en-us/help/5021671
- patchhttps://www.microsoft.com/en-us/download/details.aspx?id=104804
- referencehttps://support.microsoft.com/en-us/help/5021670
- patchhttps://www.microsoft.com/en-us/download/details.aspx?id=104805
- referencehttps://support.microsoft.com/en-us/help/5021672
- patchhttps://www.microsoft.com/en-us/download/details.aspx?id=104633
- referencehttps://support.microsoft.com/en-us/help/5019239
- patchhttps://download.microsoft.com/download/0/8/e/08e54d86-0d29-4550-b197-c312397d328b/DVD_BUILD52207.zip
- referencehttps://support.microsoft.com/en-us/topic/released-cumulative-updates-for-microsoft-dynamics-nav-2013-r2-c7f39bba-e9b2-51ac-5028-0a31b1ed6996