QID 91862
QID 91862: Microsoft Dynamics Multiple Vulnerabilities for February 2022
Microsoft Dynamics 365 is a product line of enterprise resource planning and customer relationship management intelligent business applications.
Microsoft Dynamics GP is a mid-market business accounting or enterprise resource planning (ERP) software package that uses Microsoft SQL Server to store d-ata.
CVE-2022-21957: Microsoft Dynamics 365 (on-premises) Remote Code Execution Vulnerability
CVE-2022-23269: Microsoft Dynamics GP Spoofing Vulnerability
CVE-2022-23271,CVE-2022-23272,CVE-2022-23271: Microsoft Dynamics GP Elevation of Privileges Vulnerability
CVE-2022-23274: Microsoft Dynamics GP Remote Code Execution Vulnerability
Affected Software:
Microsoft Dynamics 365 Customer Engagement (on-premises) V8.2 and V9.0
Microsoft Dynamics GP
QID Detection Logic(Authenticated):
This authenticated QID flags vulnerable systems by detecting Vulnerable versions for file Microsoft.Crm.Setup.Server.exe:
Successful exploitation of this vulnerability can result in remote code execution and escalation of privileges.
- CVE-2022-21957 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21957 - CVE-2022-23269 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-23269 - CVE-2022-23271 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-23271 - CVE-2022-23272 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-23272 - CVE-2022-23273 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-23273 - CVE-2022-23274 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-23274
CVEs related to QID 91862
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2022-23257 |
|
||
| CVE-2022-23269 |
|
||
| CVE-2022-23271 |
|
||
| CVE-2022-23272 |
|
||
| CVE-2022-23273 |
|
||
| CVE-2022-23274 |
|