CVE-2020-1018
published 2020-04-15CVE-2020-1018: An information disclosure vulnerability exists when Microsoft Dynamics Business Central/NAV on-premise does not properly hide the value of a masked field when…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
6.16%
92.6th percentile
An information disclosure vulnerability exists when Microsoft Dynamics Business Central/NAV on-premise does not properly hide the value of a masked field when showing the records as a chart page.The attacker who successfully exploited the vulnerability could see the information that are in a masked field.The security update addresses the vulnerability by updating the rendering engine the Windows client to properly detect masked fields and render the content as masked., aka 'Microsoft Dynamics Business Central/NAV Information Disclosure'.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | dynamics_365_business_central | — | — |
| microsoft | dynamics_365_business_central_2019_spring_update | — | — |
| microsoft | dynamics_nav | — | — |
| microsoft | dynamics_nav | — | — |
| microsoft | dynamics_nav | — | — |
| microsoft | dynamics_nav | — | — |
| microsoft | microsoft_dynamics_365_bc_on_premise | — | — |
| microsoft | microsoft_dynamics_nav_2015 | — | — |
| microsoft | microsoft_dynamics_nav_2016 | — | — |
| microsoft | microsoft_dynamics_nav_2017 | — | — |
| microsoft | microsoft_dynamics_nav_2018 | — | — |
| msrc | dynamics_365_business_central_2019_spring_update | — | — |
| msrc | microsoft_dynamics_365_bc_on_premise | — | — |
| msrc | microsoft_dynamics_nav_2015 | — | — |
| msrc | microsoft_dynamics_nav_2016 | — | — |
| msrc | microsoft_dynamics_nav_2017 | — | — |
| msrc | microsoft_dynamics_nav_2018 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Dynamics Business Central/NAV Information Disclosure
vendor_msrc·2020-04-14·CVSS 7.5
CVE-2020-1018 [HIGH] Microsoft Dynamics Business Central/NAV Information Disclosure
Microsoft Dynamics Business Central/NAV Information Disclosure
Description: An information disclosure vulnerability exists when Microsoft Dynamics Business Central/NAV on-premise does not properly hide the value of a masked field when showing the records as a chart page.
The attacker who successfully exploited the vulnerability could see the information that are in a masked field.
The security update addresses the vulnerability by updating the rendering engine the Windows client to properly detect masked fields and render the content as masked.
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is the entries supplied by the user in a custom form.
Microsoft Dynam
GHSA
GHSA-4hf4-8q97-rmrh: An information disclosure vulnerability exists when Microsoft Dynamics Business Central/NAV on-premise does not properly hide the value of a masked fi
ghsa_unreviewed·2022-05-24
CVE-2020-1018 [MEDIUM] GHSA-4hf4-8q97-rmrh: An information disclosure vulnerability exists when Microsoft Dynamics Business Central/NAV on-premise does not properly hide the value of a masked fi
An information disclosure vulnerability exists when Microsoft Dynamics Business Central/NAV on-premise does not properly hide the value of a masked field when showing the records as a chart page.The attacker who successfully exploited the vulnerability could see the information that are in a masked field.The security update addresses the vulnerability by updating the rendering engine the Windows client to properly detect masked fields and render the content as masked., aka 'Microsoft Dynamics Business Central/NAV Information Disclosure'.
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday — April 2020: Vulnerability disclosures and Snort coverage
blogs_talos·2020-04-14·CVSS 8.8
[HIGH] Microsoft Patch Tuesday — April 2020: Vulnerability disclosures and Snort coverage
By Jon Munshaw.
Microsoft released its monthly security update today, disclosing vulnerabilities across many of its products and releasing corresponding updates. This month's Patch Tuesday covers 115 vulnerabilities. Nineteen of the flaws Microsoft disclosed are considered critical. The remainders are scored as being “important” updates.
This month’s security update covers security issues in a variety of Microsoft services and software, including SharePoint, the Windows font library and the Windows kernel. A Cisco Talos researcher discovered CVE-2020-0939, an information disclosure vulnerability in Microsoft Media Foundation. For more, check out Talos’ full Vulnerability Spotlight here.
Talos also released a new set of SNORTⓇ rules that provide coverage for some of these vulnerabilities
Talos
Microsoft Patch Tuesday — April 2020: Vulnerability disclosures and Snort coverage
blogs_talos·2020-04-14·CVSS 8.8
[HIGH] Microsoft Patch Tuesday — April 2020: Vulnerability disclosures and Snort coverage
## Microsoft Patch Tuesday — April 2020: Vulnerability disclosures and Snort coverage
By Jon Munshaw.
Microsoft released its monthly security update today, disclosing vulnerabilities across many of its products and releasing corresponding updates. This month's Patch Tuesday covers 115 vulnerabilities. Nineteen of the flaws Microsoft disclosed are considered critical. The remainders are scored as being “important” updates.
This month’s security update covers security issues in a variety of Microsoft services and software, including SharePoint, the Windows font library and the Windows kernel. A Cisco Talos researcher discovered CVE-2020-0939 , an information disclosure vulnerability in Microsoft Media Foundation. For more, check out Talos’ full Vulnerability Spotlight here .
Talos also r
Talos
Vulnerability Spotlight: Denial-of-service vulnerability in GStreamer
blogs_talos·2020-03-23·CVSS 7.5
[HIGH] Vulnerability Spotlight: Denial-of-service vulnerability in GStreamer
Peter Wang of Cisco ASIG discovered this vulnerability. Blog by Jon Munshaw.
Cisco Talos recently discovered a denial-of-service vulnerability in GStreamer, a pipeline-based
multimedia framework. GStreamer contains gst-rtsp-server, an open-source library that allows the user to build RTSP servers. This function contains an exploit that an attacker could use to cause a null pointer deference, resulting in a denial of service.
In accordance with our coordinated disclosure policy, Cisco Talos worked with GStreamer to ensure that these issues are resolved and that an update is available for affected customers.
### Vulnerability detailsGStreamer gst-rtsp-server GstRTSPAuth denial-of-service vulnerability (TALOS-2020-1018/CVE-2020-6095)
An exploitable denial-of-service vulnerability exists
2020-04-15
Published