CVE-2024-35263: Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability

Overview

Severity
Medium (CVSS 5.7)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
Category
Information Disclosure
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2024-Jun
Released
2024-06-11
EPSS Score
5.56% (percentile: 90.3%)

FAQ

According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? Any authenticated attacker could trigger this vulnerability. It does not require admin or other elevated privileges. What type of information could be disclosed by this vulnerability? This vulnerability allows exfiltration of all the data that the logged-in user can access.

Affected Products (1)

Microsoft Dynamics

  • Microsoft Dynamics 365 (on-premises) version 9.1

Security Updates (1)

Acknowledgments

<a href="https://twitter.com/kire_devs_hacks">Erik Donker</a>

Revision History

  • 2024-06-11: Information published.