CVE-2023-38167HighCVSS 7.2

Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability

Published
August 8, 2023
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

According to the CVSS metric, privileges required is high (PR:H). What privileges does an attacker require to exploit this vulnerability? Successful exploitation of this vulnerability requires an attacker to already have admin or high privilege access to a security group within the tenant.

Is the update for Microsoft Dynamics 365 Business Central 2023 Release Wave 1 listed in this vulnerability currently available? The security update for Microsoft Dynamics 365 Business Central 2023 Release Wave 1 is not immediately available. The update will be released as soon as possible, and when it is available, customers will be notified via a revision to this CVE information. August 15. 2023 Update: The security update for Microsoft Dynamics 365 Business Central 2023 Release Wave 1 is now available. Customers running Microsoft Dynamics 365 Business Central 2023 Release Wave 1 should install the update to be protected from the vulnerability.

🎯 Affected products1

  • Microsoft Dynamics 365 Business Central 2023 Release Wave 1

✅ Remediation

KB5029765 (Security Update) — fixed build 22.0.59520

🔗 References (3)