CVE-2025-29821HighCVSS 5.5

Microsoft Dynamics Business Central Information Disclosure Vulnerability

Published
April 8, 2025
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

Improper input validation in Dynamics Business Central allows an authorized attacker to disclose information locally.

🎯 Affected products4

  • Microsoft Dynamics 365 Business Central 2023 Wave 2 – Update 23.18
  • Microsoft Dynamics 365 Business Central 2024 Wave 2 – Update 25.6
  • Microsoft Dynamics 365 Business Central 2025 Wave 1 – Update 26.0
  • Microsoft Dynamics 365 Business Central Wave 1 2024 – Update 24.12

✅ Remediation

KB5056717 (Security Update) — fixed build 24.0.32305 KB5056716 (Security Update) — fixed build 23.0.32309 KB5056718 (Security Update) — fixed build 25.2.32308 KBRelease Notes (Security Update) — fixed build 26.0.32481

🔗 References (9)