CVE-2020-0905
published 2020-03-12CVE-2020-0905: An remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerability'.
PriorityP351high8CVSS 3.1
AVNACLPRLUIRSUCHIHAH
EPSS
10.84%
95.3th percentile
An remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerability'.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | dynamics_365_business_central | — | — |
| microsoft | dynamics_365_business_central_2019_release_wave_2 | — | — |
| microsoft | dynamics_365_business_central_2019_spring_update | — | — |
| microsoft | dynamics_nav | — | — |
| microsoft | dynamics_nav | — | — |
| microsoft | dynamics_nav | — | — |
| microsoft | dynamics_nav | — | — |
| microsoft | dynamics_nav | — | — |
| microsoft | microsoft_dynamics_365_bc_on_premise | — | — |
| microsoft | microsoft_dynamics_nav_2013 | — | — |
| microsoft | microsoft_dynamics_nav_2015 | — | — |
| microsoft | microsoft_dynamics_nav_2016 | — | — |
| microsoft | microsoft_dynamics_nav_2017 | — | — |
| microsoft | microsoft_dynamics_nav_2018 | — | — |
| msrc | dynamics_365_business_central_2019_release_wave_2 | — | — |
| msrc | dynamics_365_business_central_2019_spring_update | — | — |
| msrc | microsoft_dynamics_365_bc_on_premise | — | — |
| msrc | microsoft_dynamics_nav_2013 | — | — |
| msrc | microsoft_dynamics_nav_2015 | — | — |
| msrc | microsoft_dynamics_nav_2016 | — | — |
| msrc | microsoft_dynamics_nav_2017 | — | — |
| msrc | microsoft_dynamics_nav_2018 | — | — |
CVSS provenance
nvdv3.18.0HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
vendor_msrc8.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Dynamics Business Central Remote Code Execution Vulnerability
vendor_msrc·2020-03-10·CVSS 8.0
CVE-2020-0905 [HIGH] Dynamics Business Central Remote Code Execution Vulnerability
Dynamics Business Central Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists in Microsoft Dynamics Business Central. An attacker who successfully exploited this vulnerability could execute arbitrary shell commands on victim's server.
To exploit the vulnerability, an authenticated attacker needs to convince the victim into connect to a malicious Dynamics Business Central client or elevate permission to system to perform the code execution.
The security update addresses the vulnerability by preventing the possibility of using a binary type that could eventually execute code on the victim’s server.
Microsoft Dynamics: Microsoft Dynamics
Issuing CNA: Microsoft
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest
GHSA
GHSA-3xwp-cg99-2wx2: An remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerabili
ghsa_unreviewed·2022-05-24
CVE-2020-0905 [MEDIUM] GHSA-3xwp-cg99-2wx2: An remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerabili
An remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerability'.
No detection rules found.
No public exploits indexed.
Qualys
March 2020 Patch Tuesday – 115 Vulns, 26 Critical, Microsoft Word and Workstation Patches | Qualys
blogs_qualys·2020-03-10·CVSS 8.8
[HIGH] March 2020 Patch Tuesday – 115 Vulns, 26 Critical, Microsoft Word and Workstation Patches | Qualys
This month’s Microsoft Patch Tuesday addresses 115 vulnerabilities with 26 of them labeled as Critical. Of the 26 Critical vulns, 17 are for browser and scripting engines, 4 are for Media Foundation, 2 are for GDI+ and the remaining 3 are for LNK files, Microsoft Word and Dynamics Business. Microsoft also issued a patch for an RCE in Microsoft Word. Adobe has not posted any patches for Patch Tuesday.
On the basis of volume and severity this Patch Tuesday is heavy in weight.
See details of the new detections, including description, consequence and solution.
### Workstation Patches
The Scripting Engine, LNK files (CVE-2020-0684), GDI+(CVE-2020-0831, CVE-2020-0883) and Media Foundation (CVE-2020-0801, CVE-2020-0809, CVE-2020-0807, CVE-2020-0869) patches should be prioritized for workstati
Qualys
March 2020 Patch Tuesday – 115 Vulns, 26 Critical, Microsoft Word and Workstation Patches
blogs_qualys·2020-03-10·CVSS 8.8
[HIGH] March 2020 Patch Tuesday – 115 Vulns, 26 Critical, Microsoft Word and Workstation Patches
This month’s Microsoft Patch Tuesday addresses 115 vulnerabilities with 26 of them labeled as Critical. Of the 26 Critical vulns, 17 are for browser and scripting engines, 4 are for Media Foundation, 2 are for GDI+ and the remaining 3 are for LNK files, Microsoft Word and Dynamics Business. Microsoft also issued a patch for an RCE in Microsoft Word. Adobe has not posted any patches for Patch Tuesday.
On the basis of volume and severity this Patch Tuesday is heavy in weight.
See details of the new detections , including description, consequence and solution.
## Workstation Patches
The Scripting Engine, LNK files ( CVE-2020-0684 ), GDI+( CVE-2020-0831, CVE-2020-0883 ) and Media Foundation (CVE-2020-0801, CVE-2020-0809, CVE-2020-0807, CVE-2020-0869) patches should be prioritized for works
2020-03-12
Published