KLA12313
Multiple vulnerabilities in Microsoft Dynamics

Обновлено: 14/10/2021
Дата обнаружения
12/10/2021
Уровень угрозы
High
Описание

Multiple vulnerabilities were found in Microsoft Dynamics. Malicious users can exploit these vulnerabilities to perform cross-site scripting attack, spoof user interface.

Below is a complete list of vulnerabilities:

  1. A cross-site-scripting (XSS) vulnerability in Microsoft Dynamics 365 can be exploited remotely to spoof user interface.
  2. A spoofing vulnerability in Microsoft Dynamics 365 can be exploited remotely to spoof user interface.
Пораженные продукты

Microsoft Dynamics 365 (on-premises) version 9.0
Microsoft Dynamics 365 Customer Engagement V9.1
Microsoft Dynamics 365 (on-premises) version 9.1
Microsoft Dynamics 365 Customer Engagement V9.0

Решение

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Первичный источник обнаружения
CVE-2021-40457
CVE-2021-41353
CVE-2021-41354
Оказываемое влияние
?
XSS/CSS 
[?]

SUI 
[?]
Связанные продукты
Microsoft Dynamics 365
KB list

4618795
4618810

Узнай статистику распространения уязвимостей в твоем регионе