CVE-2024-38225: Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
Overview
- Severity
- High (CVSS 8.8)
- CVSS Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- Category
- Elevation of Privilege
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2024-Sep
- Released
- 2024-09-10
- EPSS Score
- 6.12% (percentile: 90.8%)
FAQ
How could an attacker exploit this vulnerability?
An attacker needs to edit the local configuration file to contain malicious code, then send the request to the server to exploit this vulnerability.
What privileges could be gained by an attacker who successfully exploited the vulnerability?
An attacker who successfully exploited this vulnerability could gain administrator privileges.
Affected Products (3)
Microsoft Dynamics
- Microsoft Dynamics 365 Business Central 2023 Release Wave 1
- Microsoft Dynamics 365 Business Central 2024 Release Wave 1
- Microsoft Dynamics 365 Business Central 2023 Release Wave 2
Security Updates (3)
Acknowledgments
cjm00n with Cyber Kunlun & Zhiniang Peng
Revision History
- 2024-09-10: Information published.