PT-2020-4158 · Microsoft · Dynamics 365

Fabian Schmidt

·

Published

2020-09-08

·

Updated

2023-12-31

·

CVE-2020-16862

CVSS v2.0

7.3

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:P
Name of the Vulnerable Software and Affected Versions: Microsoft Dynamics 365 (on-premises) (affected versions not specified)
Description: A remote code execution issue exists due to the server's failure to properly sanitize web requests. This could allow an attacker to run arbitrary code in the context of the SQL service account by sending a specially crafted request to a vulnerable server. The issue is related to insufficient input validation.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04580
CVE-2020-16862

Affected Products

Dynamics 365