PT-2022-5866 · Microsoft · Dynamics Crm

Fabian Schmidt

·

Published

2022-09-13

·

Updated

2023-04-11

·

CVE-2022-34700

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Dynamics CRM (on-premises) (affected versions not specified)
Description The issue is related to a lack of protection for the SQL query structure in Microsoft Dynamics CRM, allowing for potential remote code execution by an attacker using specially crafted queries.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2022-07281
CVE-2022-34700

Affected Products

Dynamics Crm