QID 91978
Date Published: 2023-02-15
QID 91978: Microsoft Dynamics Security Update for February 2023
Microsoft Dynamics contains the following vulnerabilities:
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability.
Affected Software:
Microsoft Dynamics 365 (on-premises) version 9.0
Microsoft Dynamics 365 (on-premises) version 9.1
QID Detection Logic:
This QID detects vulnerable versions by checking if the version of Microsoft.Crm.Setup.Server.exe is lesser than the affected Versions:
Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges.
Solution
Customers are advised to refer to CVE-2023-21573,CVE-2023-21572,
CVE-2023-21571,
CVE-2023-21570,
CVE-2023-21807,for more details pertaining to this vulnerability.
Vendor References
- CVE-2023-21570 -
msrc.microsoft.com//update-guide/vulnerability/CVE-2023-21570 - CVE-2023-21571 -
msrc.microsoft.com//update-guide/vulnerability/CVE-2023-21571 - CVE-2023-21572 -
msrc.microsoft.com//update-guide/vulnerability/CVE-2023-21572 - CVE-2023-21573 -
msrc.microsoft.com//update-guide/vulnerability/CVE-2023-21573 - CVE-2023-21807 -
msrc.microsoft.com//update-guide/vulnerability/CVE-2023-21807
CVEs related to QID 91978
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2023-21570 |
|
||
| CVE-2023-21571 |
|
||
| CVE-2023-21572 |
|
||
| CVE-2023-21573 |
|
||
| CVE-2023-21807 |
|