CVE-2021-34474
published 2021-07-14CVE-2021-34474: Dynamics Business Central Remote Code Execution Vulnerability
PriorityP344high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
1.86%
76.7th percentile
Dynamics Business Central Remote Code Execution Vulnerability
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | dynamics_365_business_central | — | — |
| microsoft | dynamics_365_business_central | — | — |
| microsoft | microsoft_dynamics_365_business_central_2020_release_wave_1_update_16.14 | >= 16.0 < Application: 16.14.27266, Platform: 16.0.27253 | Application: 16.14.27266, Platform: 16.0.27253 |
| microsoft | microsoft_dynamics_365_business_central_2020_release_wave_2_update_17.8 | >= 17.0 < Application: 17.8.27267, Platform: 17.0.27235 | Application: 17.8.27267, Platform: 17.0.27235 |
| microsoft | microsoft_dynamics_365_business_central_2021_release_wave_1_update_18.3 | >= 18.0 < Application: 18.3.27480, Platform: 18.0.27469 | Application: 18.3.27480, Platform: 18.0.27469 |
| msrc | microsoft_dynamics_365_business_central_2020_release_wave_1_update_16.14 | — | — |
| msrc | microsoft_dynamics_365_business_central_2020_release_wave_2_update_17.8 | — | — |
| msrc | microsoft_dynamics_365_business_central_2021_release_wave_1_update_18.3 | — | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_msrc8.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x2h5-v5cw-xpq3: Dynamics Business Central Remote Code Execution Vulnerability
ghsa_unreviewed·2022-05-24
CVE-2021-34474 [HIGH] GHSA-x2h5-v5cw-xpq3: Dynamics Business Central Remote Code Execution Vulnerability
Dynamics Business Central Remote Code Execution Vulnerability
Microsoft
Dynamics Business Central Remote Code Execution Vulnerability
vendor_msrc·2021-07-13·CVSS 8.0
CVE-2021-34474 [HIGH] Dynamics Business Central Remote Code Execution Vulnerability
Dynamics Business Central Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). Can the exploit move from Dynamics Business Central to the underlying operating system?
An attacker who successfully exploited this vulnerability could use it to pivot from the machine to the rest of the network.
Dynamics Business Central Control: Dynamics Business Central Control
Microsoft: Microsoft
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://www.microsoft.com/en-us/download/details.aspx?id=103251
Reference: https://www.microsoft.com/en-us/download/details.aspx?id=10
No detection rules found.
No public exploits indexed.
Crowdstrike
July 2021 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] July 2021 Patch Tuesday: Updates and Analysis
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Crowdstrike
July 2021 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] July 2021 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
2021-07-14
Published