KLA12260
Multiple vulnerabilities in Microsoft Dynamics

Updated: 08/12/2021
Detect date
?
08/10/2021
Severity
?
High
Description

Multiple vulnerabilities were found in Microsoft Dynamics. Malicious users can exploit these vulnerabilities to execute arbitrary code, spoof user interface.

Below is a complete list of vulnerabilities:

  1. A remote code execution vulnerability in Microsoft Dynamics 365 (on-premises) can be exploited remotely to execute arbitrary code.
  2. A cross-site-scripting (XSS) vulnerability Microsoft Dynamics 365 (on-premises) can be exploited remotely to spoof user interface.
  3. A cross-site-scripting (XSS) vulnerability Microsoft Dynamics Business Central can be exploited remotely to spoof user interface.
Affected products

Microsoft Dynamics 365 Business Central 2020 Release Wave 1 - Update 16.15
Microsoft Dynamics 365 Business Central 2020 Release Wave 2 - Update 17.9
Microsoft Dynamics NAV 2018
Dynamics 365 Business Central 2019 Spring Update

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Original advisories

CVE-2021-34524
CVE-2021-36950
CVE-2021-36946

Impacts
?
ACE 
[?]

SUI 
[?]
Related products
Microsoft Dynamics 365
CVE-IDS
?
CVE-2021-345240.0Unknown
CVE-2021-369500.0Unknown
CVE-2021-369460.0Unknown
KB list

5005368
4618795
5005373
4618809
5005374
5005369
5005370
5005239

Find out the statistics of the vulnerabilities spreading in your region