QID 91964

Date Published: 2022-12-14

QID 91964: Microsoft Dynamics Security Update for December 2022

Microsoft Dynamics contains the following vulnerabilities:
Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability The security update addresses these vulnerabilities by helping to ensure that Dynamics Server properly sanitizes web requests.

Affected Software:

Microsoft Dynamics 365 Business Central 2022 Release Wave 1 - Update
Microsoft Dynamics 365 Business Central 2022 Release Wave 2 - Update
Microsoft Dynamics 365 Business Central 2021 Release Wave 1 - Update
Microsoft Dynamics 365 Business Central 2021 Release Wave 2 - Update
Microsoft Dynamics 365 Business Central 2020 Release Wave 1 - Update
Microsoft Dynamics 365 Business Central 2020 Release Wave 2 - Update
Microsoft Dynamics 365 Business Central 2019 Release Wave 2 (On-Premise)
Microsoft Dynamics 365 Business Central Spring 2019 Update
Microsoft Dynamics NAV 2018
Microsoft Dynamics NAV 2017
Microsoft Dynamics NAV 2016

QID Detection Logic:
This QID detects vulnerable software versions by fetching file versions from the following locations:
This authenticated QID flags vulnerable systems by detecting Vulnerable versions for file Microsoft.Dynamics.Nav.Server.exe

Successful exploit could compromise Confidentiality, Integrity and Availability

  • CVSS V3 rated as Critical - 8.5 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution
    Customers are advised to refer to CVE-2022-41127 for more details pertaining to this vulnerability.

    CVEs related to QID 91964

    Software Advisories
    Advisory ID Software Component Link
    CVE-2022-41127 URL Logo msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-41127