CVE-2019-1229
published 2019-08-14CVE-2019-1229: An elevation of privilege vulnerability exists in Dynamics On-Premise v9. An attacker who successfully exploited the vulnerability could leverage a customizer…
high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
An elevation of privilege vulnerability exists in Dynamics On-Premise v9. An attacker who successfully exploited the vulnerability could leverage a customizer privilege within Dynamics to gain control of the Web Role hosting the Dynamics installation.
To exploit this vulnerability, an attacker needs to have credentials for a user that has permission to author customized business rules in Dynamics, and persist XAML script in a way that causes it to be interpreted as code.
The update addresses the vulnerability by restricting XAML activities to a whitelisted set.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | dynamics_365 | — | — |
| microsoft | microsoft_dynamics_365_version_9.0 | >= 9.0.0 < publication | publication |
| msrc | microsoft_dynamics_365_version_9.0 | — | — |