Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.3epss 1.0%
exploitation probability
1.0%top 41% of all CVEs
observed exploitation
nono source reports it
In short
A flaw in Microsoft Dynamics 365 Business Central allows an authenticated user to gain higher privileges than they should have. This could let someone access sensitive business data or perform actions they're not supposed to.
Technical detail
An elevation of privilege vulnerability in Dynamics 365 Business Central permits authenticated attackers to escalate their user permissions beyond their assigned role. The vulnerability affects the privilege management mechanism (CWE-1390), potentially enabling unauthorized access to sensitive business operations and data.
Summary generated and translated by AI from the official description.
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C