CVE-2024-38182
Microsoft Dynamics 365 Elevation of Privilege Vulnerability
In short
Microsoft Dynamics 365 has weak authentication that allows someone without proper credentials to gain elevated permissions remotely. This is critical because attackers can take control of business systems and access sensitive data.
Technical detail
The vulnerability involves insufficient authentication mechanisms in Microsoft Dynamics 365, enabling unauthenticated remote attackers to achieve privilege escalation. Attack vectors include network-based exploitation without valid credentials; the impact includes unauthorized administrative access to the system.
Summary generated and translated by AI from the official description.
Weak authentication in Microsoft Dynamics 365 allows an unauthenticated attacker to elevate privileges over a network.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
Affected products
Microsoft · Dynamics 365 Field Service (on-premises) v7 seriesWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →