CVE-2020-17152
published 2020-12-10CVE-2020-17152: Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability
PriorityP355high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.75%
84.5th percentile
Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | dynamics_365 | < 10.0.11 | 10.0.11 |
| microsoft | dynamics_365_for_finance_and_operations | >= 10.0.0 < publication | publication |
| msrc | dynamics_365_for_finance_and_operations | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- ·Exploitation requires authenticated access (low privilege); unauthenticated exploitation is not possible. ↗
- ·Exploitation is rated 'More Likely' for both latest and older software releases, indicating active exploitation risk despite no confirmed in-the-wild exploitation at time of disclosure. ↗
- ·Affected product is Microsoft Dynamics 365 for Finance and Operations (on-premises) only; cloud/SaaS deployments may differ in exposure. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability
vendor_msrc·2020-12-08·CVSS 8.8
CVE-2020-17152 [HIGH] Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability
Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?
The attacker must be authenticated to be able to exploit this vulnerability.
Microsoft Dynamics: Microsoft Dynamics
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely;Older Software Release:Exploitation More Likely
Remediation: Release Notes
Reference: https://docs.microsoft.com/en-us/dynamics365/fin-ops-core/dev-itpro/migration-upgrade/download-hotfix-lcs
Reference: https://docs.microsoft.com/en-us/dynamics365/fin-ops-core/dev-itpro/get-start
GHSA
GHSA-46j6-cp62-x453: , aka 'Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability'
ghsa_unreviewed·2022-05-24·CVSS 8.8
CVE-2020-17152 [HIGH] CWE-94 GHSA-46j6-cp62-x453: , aka 'Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability'
, aka 'Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-17158.
GHSA
GHSA-3rhq-qjcj-26w7: , aka 'Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability'
ghsa_unreviewed·2022-05-24·CVSS 8.8
CVE-2020-17158 [HIGH] CWE-94 GHSA-3rhq-qjcj-26w7: , aka 'Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability'
, aka 'Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-17152.
No detection rules found.
No public exploits indexed.
Checkpoint
14th December – Threat Intelligence Bulletin
blogs_checkpoint·2020-12-14
CVE-2020-1971 14th December – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 14th December – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 14th December, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
The US Treasury Department and US Department of Commerce were victims of a cyberattack compromising their internal email traffic. Perhaps related , SolarWinds IT management software has been exploited in a supply chain attack, adding malicious code to its software updates released between March and June 2020.
Habana
Trendmicro
December Patch Tuesday Fixes Exchange, SMB
blogs_trendmicro·2020-12-09·CVSS 6.6
[MEDIUM] December Patch Tuesday Fixes Exchange, SMB
# December Patch Tuesday Fixes Exchange, SMB
The last set of updates for the year includes 58 patches for the Microsoft Office suite.
By: Trend Micro
2020/12/09
Read time: ( words)
Save to Folio
Updated on 12/9/2020 02:37PM PST to include Trend Micro Deep Security and Vulnerability Protection rules.
The last set of updates for the year includes 58 patches for the Microsoft Office suite. Of the total number, nine have been rated Critical and 46 as Important. A significant number of updates fixes gaps in MS Exchange vulnerable to remote code execution (RCE) and information disclosure, as well as a server message block (SMB) gap also noted for the latter vulnerability. No zero days have been observed, though several vulnerabilities have been deemed as likely for abuse. Six of the total
2020-12-10
Published