Unrated severityNVD Advisory· Published Sep 11, 2020· Updated Nov 18, 2024
Microsoft Dynamics 365 (on-premises) Remote Code Execution Vulnerability
CVE-2020-16862
Description
<p>A remote code execution vulnerability exists in Microsoft Dynamics 365 (on-premises) when the server fails to properly sanitize web requests to an affected Dynamics server. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SQL service account. An authenticated attacker could exploit this vulnerability by sending a specially crafted request to a vulnerable Dynamics server. The security update addresses the vulnerability by correcting how Microsoft Dynamics 365 (on-premises) validates and sanitizes user input.</p>
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16862mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.