← back
CVE-2024-38182criticalCWE-1390

Microsoft Dynamics 365 Elevation of Privilege Vulnerability

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9epss 0.9%
exploitation probability
0.9%top 42% of all CVEs
observed exploitation
nono source reports it
In short

Microsoft Dynamics 365 has weak authentication that allows someone without proper credentials to gain elevated permissions remotely. This is critical because attackers can take control of business systems and access sensitive data.

Technical detail

The vulnerability involves insufficient authentication mechanisms in Microsoft Dynamics 365, enabling unauthenticated remote attackers to achieve privilege escalation. Attack vectors include network-based exploitation without valid credentials; the impact includes unauthorized administrative access to the system.

Summary generated and translated by AI from the official description.
Weak authentication in Microsoft Dynamics 365 allows an unauthenticated attacker to elevate privileges over a network.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C