CVE-2025-29821HighCVSS 5.5
Microsoft Dynamics Business Central Information Disclosure Vulnerability
🔗 CVE IDs covered (1)
📋 Description
Improper input validation in Dynamics Business Central allows an authorized attacker to disclose information locally.
🎯 Affected products4
- Microsoft Dynamics 365 Business Central 2023 Wave 2 – Update 23.18
- Microsoft Dynamics 365 Business Central 2024 Wave 2 – Update 25.6
- Microsoft Dynamics 365 Business Central 2025 Wave 1 – Update 26.0
- Microsoft Dynamics 365 Business Central Wave 1 2024 – Update 24.12
✅ Remediation
KB5056717 (Security Update) — fixed build 24.0.32305 KB5056716 (Security Update) — fixed build 23.0.32309 KB5056718 (Security Update) — fixed build 25.2.32308 KBRelease Notes (Security Update) — fixed build 26.0.32481
🔗 References (9)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29821
- patchhttps://download.microsoft.com/download/8be3cb71-652c-44cf-91f7-f0079d79a67e/Dynamics.365.BC.32447.US.DVD.zip
- referencehttps://support.microsoft.com/en-us/help/5056717
- patchhttps://download.microsoft.com/download/74eaf1bd-a1d3-4b8b-a688-dd1857c0a61c/Dynamics.365.BC.32409.US.DVD.zip
- referencehttps://support.microsoft.com/en-us/help/5056716
- patchhttps://download.microsoft.com/download/cd199d92-3b8f-4c03-935f-23f6636e5229/Dynamics.365.BC.32556.US.DVD.zip
- referencehttps://support.microsoft.com/en-us/help/5056718
- patchhttps://download.microsoft.com/download/840ce874-dbc3-430f-a17e-6ed5d9d465bf/Dynamics.365.BC.32481.US.DVD.zip
- referencehttps://learn.microsoft.com/en-us/dynamics365/business-central/dev-itpro/whatsnew/whatsnew-update-26-0