CVE-2023-36566HighCVSS 6.5
Microsoft Common Data Model SDK Denial of Service Vulnerability
🔗 CVE IDs covered (1)
📋 Description
According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges.
🎯 Affected products4
- Microsoft Common Data Model SDK for C#
- Microsoft Common Data Model SDK for Java
- Microsoft Common Data Model SDK for Python
- Microsoft Common Data Model SDK for TypeScript
✅ Remediation
KBRelease Notes (Security Update) — fixed build 1.7.4
🔗 References (6)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36566
- patchhttps://central.sonatype.com/artifact/com.microsoft.commondatamodel/objectmodel?smo=true
- referencehttps://github.com/microsoft/CDM
- patchhttps://www.npmjs.com/package/cdm.objectmodel
- patchhttps://pypi.org/project/commondatamodel-objectmodel/
- patchhttps://www.nuget.org/profiles/CommonDataModel/