Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2022-34700

Опубликовано: 13 сент. 2022
Источник: msrc
CVSS3: 8.8
EPSS Низкий

Описание

Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability

FAQ

How could an attacker exploit this vulnerability?

An authenticated user could run a specially crafted trusted solution package to execute arbitrary SQL commands. From there the attacker could escalate and execute commands as db_owner within their Dynamics CRM database.

According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?

The attacker must be authenticated to be able to exploit this vulnerability.

Обновления

ПродуктСтатьяОбновление
Microsoft Dynamics CRM (on-premises) 9.1
Microsoft Dynamics CRM (on-premises) 9.0

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 79%
0.01273
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
больше 3 лет назад

Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability

CVSS3: 8.8
github
больше 3 лет назад

Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-35805.

CVSS3: 8.8
fstec
больше 3 лет назад

Уязвимость программного средства для планирования ресурсов Microsoft Dynamics CRM, связанная с непринятием мер по защите структуры запроса SQL, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 79%
0.01273
Низкий

8.8 High

CVSS3