← back
CVE-2024-38182

Microsoft Dynamics 365 Elevation of Privilege Vulnerability

CVSS 9 CRITICALEPSS 0.9%CWE-1390
In short

Microsoft Dynamics 365 has weak authentication that allows someone without proper credentials to gain elevated permissions remotely. This is critical because attackers can take control of business systems and access sensitive data.

Technical detail

The vulnerability involves insufficient authentication mechanisms in Microsoft Dynamics 365, enabling unauthenticated remote attackers to achieve privilege escalation. Attack vectors include network-based exploitation without valid credentials; the impact includes unauthorized administrative access to the system.

Summary generated and translated by AI from the official description.
Weak authentication in Microsoft Dynamics 365 allows an unauthenticated attacker to elevate privileges over a network.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →