KLA20124
ACE vulnerability in Microsoft Dynamics

Updated: 01/09/2023
Detect date
?
12/13/2022
Severity
?
Critical
Description

Code execution vulnerability was found in Microsoft Dynamics. Malicious users can exploit this vulnerability to execute arbitrary code.

Affected products

Microsoft Dynamics NAV 2016
Microsoft Dynamics NAV 2018
Dynamics 365 Business Central 2019 Release Wave 2 (On-Premise)
Microsoft Dynamics 365 Business Central 2021 Release Wave 1
Microsoft Dynamics 365 Business Central 2022 Release Wave 2
Microsoft Dynamics NAV 2017
Microsoft Dynamics 365 Business Central 2021 Release Wave 2
Microsoft Dynamics 365 Business Central 2020 Release Wave 2
Microsoft Dynamics 365 Business Central 2020 Release Wave 1
Microsoft Dynamics 365 Business Central 2022 Release Wave 1
Dynamics 365 Business Central Spring 2019 Update

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Original advisories

CVE-2022-41127

Impacts
?
ACE 
[?]
Related products
Microsoft Dynamics 365
KB list

5010202
5019239
5021671
5010910
5021670
5013420
5021672
5021668
5005293
5021669
5001733

Microsoft official advisories
Microsoft Security Update Guide
Find out the statistics of the vulnerabilities spreading in your region