KLA11576
Spoofing vulnerability in Microsoft Dynamics
Обновлено: 11/10/2019
Дата обнаружения
08/10/2019
Уровень угрозы
High
Описание

A cross-site-scripting (XSS) vulnerability was found in Microsoft Dynamics. Malicious users can exploit remotely via specially crafted web request to spoof user interface.

Пораженные продукты

Microsoft Dynamics 365 (on-premises) version 9.0

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
CVE-2019-1375
Оказываемое влияние
?
SUI 
[?]
Связанные продукты
Microsoft Dynamics 365
CVE-IDS
CVE-2019-13750.0Unknown
KB list

4515519

Microsoft official advisories
Microsoft Security Update Guide