PT-2020-4158 · Microsoft · Dynamics 365
Fabian Schmidt
·
Published
2020-09-08
·
Updated
2023-12-31
·
CVE-2020-16862
CVSS v2.0
7.3
High
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:P |
Name of the Vulnerable Software and Affected Versions:
Microsoft Dynamics 365 (on-premises) (affected versions not specified)
Description:
A remote code execution issue exists due to the server's failure to properly sanitize web requests. This could allow an attacker to run arbitrary code in the context of the SQL service account by sending a specially crafted request to a vulnerable server. The issue is related to insufficient input validation.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dynamics 365