Описание
Microsoft Dynamics On-Premise Security Feature Bypass
A security feature bypass vulnerability exists in Dynamics On Premise. An attacker who exploited the vulnerability could send attachment types that are blocked by the email attachment system.
To exploit the vulnerability, an attacker would need to capture and edit the POST request to include a special character in the extension.
The update addresses the vulnerability by blocking files with the special character in the file extension.
Обновления
Продукт | Статья | Обновление |
---|---|---|
Microsoft Dynamics 365 (on-premises) version 8.2 | ||
Microsoft Dynamics 365 (on-premises) version 9.0 | ||
Microsoft Dynamics CRM 2015 (on-premises) version 7.0 |
Показывать по
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
Older Software Release
EPSS
Связанные уязвимости
A security feature bypass vulnerability exists in Dynamics On Premise, aka 'Microsoft Dynamics On-Premise Security Feature Bypass'.
A security feature bypass vulnerability exists in Dynamics On Premise, aka 'Microsoft Dynamics On-Premise Security Feature Bypass'.
Уязвимость программного средства для планирования ресурсов Microsoft Dynamics, связанная с ошибками в настройках безопасности, позволяющая нарушителю обойти существующие ограничения на вложенные файлы электронной почты
EPSS