QID 91792
Date Published: 2021-07-14
QID 91792: Microsoft Dynamics Business Central Remote Code Execution (RCE) Vulnerability July 2021
Microsoft Dynamics is prone to remote code execution vulnerability.
KB Articles associated with this update are: KB5004715, KB5004716, 5004717
Affected Software:
Microsoft Dynamics 365 Business Central 2021 Release Wave 1 - Update 18.3
Microsoft Dynamics 365 Business Central 2020 Release Wave 2 - Update 17.8
Microsoft Dynamics 365 Business Central 2020 Release Wave 1 - Update 16.14
QID Detection Logic(Authenticated):
This authenticated QID flags vulnerable systems by detecting Vulnerable versions for file Microsoft.Dynamics.Nav.Server.exe
An attacker who successfully exploited this vulnerability could use it to pivot from the machine to the rest of the network.
Solution
Vendor References
- KB5004715 -
support.microsoft.com/en-us/help/5004715 - KB5004716 -
support.microsoft.com/en-us/help/5004716 - KB5004717 -
support.microsoft.com/en-us/help/5004717
CVEs related to QID 91792
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| KB5004715 |
|
||
| KB5004716 |
|
||
| KB5004717 |
|