QID 92122
Date Published: 2024-03-13
QID 92122: Microsoft Dynamics 365 Security Update for March 2024
Microsoft Dynamics 365 is a product line of enterprise resource planning and customer relationship management intelligent business applications.
The March 2024 update for Microsoft Dynamics 365 fixes the following vulnerability:
- CVE-2024-21419: Microsoft Dynamics 365 (on-premises) cross-site scripting (XSS) vulnerability
Microsoft Dynamics 365 (on-premises) version 9.1
QID Detection Logic(Authenticated):
This authenticated QID flags vulnerable systems by detecting Vulnerable versions for file Microsoft.Crm.Setup.Server.exe:
Successful exploitation allows an unauthenticated, remote attacker to conduct cross-site scripting (XSS) vulnerability attacks on a targeted system.
Solution
Customers are advised to refer to refer to CVE-2024-21419 for more details pertaining to this vulnerability.
Vendor References
- CVE-2024-21419 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-21419
CVEs related to QID 92122
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2024-21419 |
|