CVE-2019-1008
published 2019-05-16CVE-2019-1008: A security feature bypass vulnerability exists in Dynamics On Premise, aka 'Microsoft Dynamics On-Premise Security Feature Bypass'.
PriorityP432medium5.9CVSS 3.0
AVNACHPRNUINSUCNIHAN
EPSS
2.76%
84.6th percentile
A security feature bypass vulnerability exists in Dynamics On Premise, aka 'Microsoft Dynamics On-Premise Security Feature Bypass'.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | dynamics_365 | — | — |
| microsoft | dynamics_365 | — | — |
| microsoft | dynamics_crm_2015 | — | — |
| microsoft | microsoft_dynamics_365 | — | — |
| microsoft | microsoft_dynamics_365 | — | — |
| microsoft | microsoft_dynamics_crm_2015 | — | — |
| msrc | microsoft_dynamics_365_version_8.2 | — | — |
| msrc | microsoft_dynamics_365_version_9.0 | — | — |
| msrc | microsoft_dynamics_crm_2015_version_7.0 | — | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_msrc5.9HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Dynamics On-Premise Security Feature Bypass
vendor_msrc·2019-05-14·CVSS 5.9
CVE-2019-1008 [MEDIUM] Microsoft Dynamics On-Premise Security Feature Bypass
Microsoft Dynamics On-Premise Security Feature Bypass
Description: A security feature bypass vulnerability exists in Dynamics On Premise. An attacker who exploited the vulnerability could send attachment types that are blocked by the email attachment system.
To exploit the vulnerability, an attacker would need to capture and edit the POST request to include a special character in the extension.
The update addresses the vulnerability by blocking files with the special character in the file extension.
Microsoft Dynamics: Microsoft Dynamics
Impact: Security Feature Bypass
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely
Reference: https://www.microsoft.com/downloads/details.aspx?familyid=b2
GHSA
GHSA-8w8m-w63v-5jcc: A security feature bypass vulnerability exists in Dynamics On Premise, aka 'Microsoft Dynamics On-Premise Security Feature Bypass'
ghsa_unreviewed·2022-05-24
CVE-2019-1008 [MEDIUM] GHSA-8w8m-w63v-5jcc: A security feature bypass vulnerability exists in Dynamics On Premise, aka 'Microsoft Dynamics On-Premise Security Feature Bypass'
A security feature bypass vulnerability exists in Dynamics On Premise, aka 'Microsoft Dynamics On-Premise Security Feature Bypass'.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-05-16
Published