QID 92086
QID 92086: Microsoft Dynamics 365 Finance and Operations Denial of Service Vulnerability for December 2023
Microsoft Dynamics 365 is a product line of enterprise resource planning and customer relationship management intelligent business applications.
Microsoft Dynamics 365 contains a cross-site scripting vulnerability that could be exploited by an unauthenticated, remote attacker to execute malicious scripts under the security context of the targeted user.
Affected Software:
Dynamics 365 for Finance and Operations Platform Update 60
Dynamics 365 for Finance and Operations Version 10.0.37 Platform Update 61
Dynamics 365 for Finance and Operations Version 10.0.38 Platform Update 62
Microsoft Dynamics 365 (on-premises) version 9.0
Microsoft Dynamics 365 (on-premises) version 9.1
QID Detection Logic(Authenticated):
This authenticated QID flags vulnerable systems by detecting Vulnerable versions for file Microsoft.Crm.Setup.Server.exe:
Successful exploitation allows an unauthenticated, remote attacker to execute malicious scripts under the security context of the targeted user.
- CVE-2023-35621 -
msrc.microsoft.com/update-guide/en-US/advisory/CVE-2023-35621 - CVE-2023-36020 -
msrc.microsoft.com/update-guide/en-US/advisory/CVE-2023-36020
CVEs related to QID 92086
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2023-35621 |
|
||
| CVE-2023-36020 |
|