CVE-2023-24922HighCVSS 6.5

Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability

Published
March 14, 2023
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

What type of information could be disclosed by this vulnerability? This vulnerability causes a verbose error message that could provide attacker with enough information to construct a malicious payload.

According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges.

🎯 Affected products2

  • Microsoft Dynamics 365 (on-premises) version 9.0
  • Microsoft Dynamics 365 (on-premises) version 9.1

✅ Remediation

KB5023506 (Security Update) — fixed build 9.0.45.11 KB5023505 (Security Update) — fixed build 9.1.16.20

🔗 References (3)