Back

HIGH

Dynamics On-Premise Elevation of Privilege Vulnerability

Published Aug 14, 2019

Description

An elevation of privilege vulnerability exists in Dynamics On-Premise v9. An attacker who successfully exploited the vulnerability could leverage a customizer privilege within Dynamics to gain control of the Web Role hosting the Dynamics installation. To exploit this vulnerability, an attacker needs to have credentials for a user that has permission to author customized business rules in Dynamics, and persist XAML script in a way that causes it to be interpreted as code. The update addresses the vulnerability by restricting XAML activities to a whitelisted set.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (0)

No CWE recorded.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner microsoft
Published Aug 14, 2019
Updated Aug 4, 2024
Reserved Nov 26, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner microsoft
Published Aug 14, 2019
Updated Aug 4, 2024
Exploited since n/a
EUVD-2019-9796