CVE-2023-24922HighCVSS 6.5
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
🔗 CVE IDs covered (1)
📋 Description
What type of information could be disclosed by this vulnerability? This vulnerability causes a verbose error message that could provide attacker with enough information to construct a malicious payload.
According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges.
🎯 Affected products2
- Microsoft Dynamics 365 (on-premises) version 9.0
- Microsoft Dynamics 365 (on-premises) version 9.1
✅ Remediation
KB5023506 (Security Update) — fixed build 9.0.45.11 KB5023505 (Security Update) — fixed build 9.1.16.20