Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-55f5-7786-m5m5

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

A remote code execution vulnerability exists in Microsoft Dynamics 365 for Finance and Operations (on-premises) version 10.0.11, aka 'Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability'.

A remote code execution vulnerability exists in Microsoft Dynamics 365 for Finance and Operations (on-premises) version 10.0.11, aka 'Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability'.

EPSS

Процентиль: 49%
0.00259
Низкий

7.1 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.1
nvd
больше 5 лет назад

<p>A remote code execution vulnerability exists in Microsoft Dynamics 365 for Finance and Operations (on-premises) version 10.0.11. An attacker who successfully exploited this vulnerability could gain remote code execution via server-side script execution on the victim server.</p> <p>An authenticated attacker with privileges to import and export data could exploit this vulnerability by sending a specially crafted file to a vulnerable Dynamics server.</p> <p>The security update addresses the vulnerability by correcting how Microsoft Dynamics 365 for Finance and Operations (on-premises) version 10.0.11 handles user input.</p>

CVSS3: 7.1
msrc
больше 5 лет назад

Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability

CVSS3: 7.1
fstec
больше 5 лет назад

Уязвимость программного средства для планирования ресурсов Microsoft Dynamics 365 for Finance and Operations, связанная с ошибками обработки входных данных, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 49%
0.00259
Низкий

7.1 High

CVSS3

Дефекты

CWE-20