QID 91981
Date Published: 2023-02-15
QID 91981: Microsoft Dynamics Unified Service Desk Remote Code Execution (RCE) Vulnerability
Unified Service Desk assists an agent to view the data stored in the Dynamic 365 Customer Engagement app in a holistic manner.
CVE-2023-21778:Microsoft Dynamics Unified Service Desk Remote Code Execution Vulnerability.
Affected Software:
Microsoft Dynamics Unified Service Desk prior to 4.2.0.51.
QID Detection Logic(Authenticated):
This authenticated QID flags vulnerable systems by detecting Vulnerable versions for file UnifiedServiceDesk.exe.
The attacker might be able to call victim's local files in the Resources directory and execute Windows commands that are outside of the Dynamics application.
Solution
Customers are advised to refer to CVE-2023-21778
Vendor References
- CVE-2023-21778 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21778
CVEs related to QID 91981
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2023-21778 |
|