cbcvebase.
CVE-2022-23259
published 2022-04-15

CVE-2022-23259: Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability

PriorityP357high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.78%
84.8th percentile
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability

Affected

6 ranges
VendorProductVersion rangeFixed in
microsoftdynamics_365
microsoftdynamics_365
microsoftmicrosoft_dynamics_365_version_9.0>= 9.0.0 < 9.0.37.29.0.37.2
microsoftmicrosoft_dynamics_365_version_9.1>= 9.0 < 9.1.9.89.1.9.8
msrcmicrosoft_dynamics_365_version_9.0
msrcmicrosoft_dynamics_365_version_9.1

Detection & IOCsextracted from sources · hover to see the quote

  • An authenticated user running a specially crafted trusted solution package to execute arbitrary SQL commands should be monitored for anomalous SQL activity within the Dynamics CRM database.
  • Monitor for privilege escalation to db_owner role within the Dynamics CRM database, which may indicate post-exploitation activity following malicious solution package execution.
  • ·Exploitation requires an authenticated user, limiting the attack surface to users with access to deploy trusted solution packages in Microsoft Dynamics 365 On-Premises.
  • ·As of the advisory, this vulnerability has not been publicly disclosed or exploited in the wild; exploitation is rated 'Less Likely' for both latest and older software releases.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.