CVE-2024-38225: Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability

Overview

Severity
High (CVSS 8.8)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Category
Elevation of Privilege
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2024-Sep
Released
2024-09-10
EPSS Score
6.12% (percentile: 90.8%)

FAQ

How could an attacker exploit this vulnerability? An attacker needs to edit the local configuration file to contain malicious code, then send the request to the server to exploit this vulnerability. What privileges could be gained by an attacker who successfully exploited the vulnerability? An attacker who successfully exploited this vulnerability could gain administrator privileges.

Affected Products (3)

Microsoft Dynamics

  • Microsoft Dynamics 365 Business Central 2023 Release Wave 1
  • Microsoft Dynamics 365 Business Central 2024 Release Wave 1
  • Microsoft Dynamics 365 Business Central 2023 Release Wave 2

Security Updates (3)

Acknowledgments

cjm00n with Cyber Kunlun & Zhiniang Peng

Revision History

  • 2024-09-10: Information published.