CVE-2021-42316
published 2021-11-10CVE-2021-42316: Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
PriorityP356high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.15%
80.1th percentile
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | dynamics_365 | — | — |
| microsoft | dynamics_365 | — | — |
| microsoft | microsoft_dynamics_365_version_9.0 | >= 9.0.0 < 9.0.34.5 | 9.0.34.5 |
| microsoft | microsoft_dynamics_365_version_9.1 | >= 9.0 < 9.1.6.3 | 9.1.6.3 |
| msrc | microsoft_dynamics_365_version_9.0 | — | — |
| msrc | microsoft_dynamics_365_version_9.1 | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
vendor_msrc·2021-11-09·CVSS 8.8
CVE-2021-42316 [HIGH] Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
FAQ: What privileges could an attacker gain with successful exploitation of this vulnerability?
An attacker can write to any file where the webserver user (nt authority\network service) has write access.
Microsoft Dynamics: Microsoft Dynamics
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely
Reference: https://www.microsoft.com/en-us/download/details.aspx?id=103648
Reference: https://support.microsoft.com/help/5008478
Reference: https://www.microsoft.com/en-us/download/details.aspx?id=103647
Reference: https://support.microsoft.com/he
GHSA
GHSA-9355-j2r6-jmg6: Microsoft Dynamics 365 (on-premises) Remote Code Execution Vulnerability
ghsa_unreviewed·2022-05-24
CVE-2021-42316 [HIGH] GHSA-9355-j2r6-jmg6: Microsoft Dynamics 365 (on-premises) Remote Code Execution Vulnerability
Microsoft Dynamics 365 (on-premises) Remote Code Execution Vulnerability
No detection rules found.
No public exploits indexed.
Qualys
Microsoft & Adobe Patch Tuesday (November 2021) – Microsoft 55 Vulnerabilities with 6 Critical, 6 Zero-Days. Adobe 4 Vulnerabilities | Qualys
blogs_qualys·2021-11-11·CVSS 9.0
CVE-2021-42298 [CRITICAL] Microsoft & Adobe Patch Tuesday (November 2021) – Microsoft 55 Vulnerabilities with 6 Critical, 6 Zero-Days. Adobe 4 Vulnerabilities | Qualys
#### Table of Contents
- Microsoft Patch Tuesday November 2021
- Adobe Patch Tuesday October 2021
- Discover Patch Tuesday Vulnerabilities in VMDR
- Respond by Patching
- Patch Tuesday Dashboard
- About Patch Tuesday
## Microsoft Patch Tuesday – November 2021
Microsoft patched 55 vulnerabilities in their November 2021 Patch Tuesday release, of which six are rated as critical severity and six were previously reported as zero-days.
### Critical Microsoft Vulnerabilities Patched
CVE-2021-42298 – Microsoft Defender Remote Code Execution Vulnerability
This vulnerability in Microsoft Defender can be exploited using Maliciously crafted files. The remote code execution vulnerability will be triggered when the malicious file is opened by a user or scanned automatically via an outdated version
Qualys
Microsoft & Adobe Patch Tuesday (November 2021) – Microsoft 55 Vulnerabilities with 6 Critical, 6 Zero-Days. Adobe 4 Vulnerabilities
blogs_qualys·2021-11-11·CVSS 9.0
CVE-2021-42298 [CRITICAL] Microsoft & Adobe Patch Tuesday (November 2021) – Microsoft 55 Vulnerabilities with 6 Critical, 6 Zero-Days. Adobe 4 Vulnerabilities
## Table of Contents
Microsoft Patch Tuesday November 2021
Adobe Patch Tuesday October 2021
Discover Patch Tuesday Vulnerabilities in VMDR
Respond by Patching
Patch Tuesday Dashboard
About Patch Tuesday
## Microsoft Patch Tuesday – November 2021
Microsoft patched 55 vulnerabilities in their November 2021 Patch Tuesday release, of which six are rated as critical severity and six were previously reported as zero-days.
## Critical Microsoft Vulnerabilities Patched
CVE-2021-42298 – Microsoft Defender Remote Code Execution Vulnerability
This vulnerability in Microsoft Defender can be exploited using Maliciously crafted files. The remote code execution vulnerability will be triggered when the malicious file is opened by a user or scanned automatically via an outdated version of Micros
Crowdstrike
November 2021 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] November 2021 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Crowdstrike
November 2021 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] November 2021 Patch Tuesday: Updates and Analysis
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
2021-11-10
Published