KLA12313
Multiple vulnerabilities in Microsoft Dynamics

Updated: 10/14/2021
Detect date
?
10/12/2021
Severity
?
High
Description

Multiple vulnerabilities were found in Microsoft Dynamics. Malicious users can exploit these vulnerabilities to perform cross-site scripting attack, spoof user interface.

Below is a complete list of vulnerabilities:

  1. A cross-site-scripting (XSS) vulnerability in Microsoft Dynamics 365 can be exploited remotely to spoof user interface.
  2. A spoofing vulnerability in Microsoft Dynamics 365 can be exploited remotely to spoof user interface.
Affected products

Microsoft Dynamics 365 (on-premises) version 9.0
Microsoft Dynamics 365 Customer Engagement V9.1
Microsoft Dynamics 365 (on-premises) version 9.1
Microsoft Dynamics 365 Customer Engagement V9.0

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Original advisories

CVE-2021-40457
CVE-2021-41353
CVE-2021-41354

Impacts
?
XSS/CSS 
[?]

SUI 
[?]
Related products
Microsoft Dynamics 365
KB list

4618795
4618810

Find out the statistics of the vulnerabilities spreading in your region