CVE-2024-21395HighCVSS 8.2

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

Published
February 13, 2024
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? The user would have to click on a specially crafted URL to be compromised by the attacker.

According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of integrity (I:L)? What does that mean for this vulnerability? The attacker is only able to modify the content of the vulnerable link to redirect the victim to a malicious site.

According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability? The vulnerability is in the web server, but the malicious scripts execute in the victim’s browser on their machine.

🎯 Affected products1

  • Microsoft Dynamics 365 (on-premises) version 9.1

✅ Remediation

KB5035110 (Security Update) — fixed build 9.1.25.17

🔗 References (3)