QID 92114
Date Published: 2024-02-19
QID 92114: Microsoft Dynamics 365 Security Update for February 2024
Microsoft Dynamics 365 is a product line of enterprise resource planning and customer relationship management intelligent business applications.
The February 2024 update for Microsoft Dynamics 365 fixes the following vulnerabilities:
- CVE-2024-21327: Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability
- CVE-2024-21328: Dynamics 365 Sales Spoofing Vulnerability
- CVE-2024-21380: Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability
- CVE-2024-21389: Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
- CVE-2024-21393: Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
- CVE-2024-21394: Dynamics 365 Field Service Spoofing Vulnerability
- CVE-2024-21395: Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
- CVE-2024-21396: Dynamics 365 Sales Spoofing Vulnerability
Microsoft Dynamics 365 Customer Engagement V9.1
Microsoft Dynamics 365 (on-premises) prior to 9.1
Microsoft Dynamics 365 Business Central 2023 Release Wave 2
Microsoft Dynamics 365 Business Central 2023 Release Wave 1
QID Detection Logic(Authenticated):
This authenticated QID flags vulnerable systems by detecting Vulnerable versions for file Microsoft.Crm.Setup.Server.exe:
Depending on the vulnerability being exploited, an attacker could exploit these vulnerabilities to conduct cross-site scripting vulnerabilities or spoof content.
Solution
Customers are advised to refer to refer to CVE-2024-21327, CVE-2024-21328, CVE-2024-21380, CVE-2024-21389, CVE-2024-21393, CVE-2024-21394, CVE-2024-21395 or CVE-2024-21396 for more details pertaining to this vulnerability.
Vendor References
- CVE-2024-21327 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-21327 - CVE-2024-21328 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-21328 - CVE-2024-21380 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-21380 - CVE-2024-21389 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-21389 - CVE-2024-21393 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-21393 - CVE-2024-21394 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-21394 - CVE-2024-21395 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-21395 - CVE-2024-21396 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-21396
CVEs related to QID 92114
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2024-21327 |
|
||
| CVE-2024-21328 |
|
||
| CVE-2024-21380 |
|
||
| CVE-2024-21389 |
|
||
| CVE-2024-21393 |
|
||
| CVE-2024-21394 |
|
||
| CVE-2024-21395 |
|
||
| CVE-2024-21396 |
|