PT-2020-4022 · Microsoft · Dynamics 365

Ashar Javed

·

Published

2020-09-08

·

Updated

2023-12-31

·

CVE-2020-16860

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Microsoft Dynamics 365 (on-premises) (affected versions not specified)
Description: A remote code execution issue exists due to the server's failure to properly sanitize web requests. An authenticated attacker could exploit this by sending a specially crafted request, potentially allowing them to run arbitrary code in the context of the SQL service account. The issue is related to insufficient input validation.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

BDU:2020-04422
CVE-2020-16860

Affected Products

Dynamics 365