CVE-2022-23259
published 2022-04-15CVE-2022-23259: Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
PriorityP357high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.78%
84.8th percentile
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | dynamics_365 | — | — |
| microsoft | dynamics_365 | — | — |
| microsoft | microsoft_dynamics_365_version_9.0 | >= 9.0.0 < 9.0.37.2 | 9.0.37.2 |
| microsoft | microsoft_dynamics_365_version_9.1 | >= 9.0 < 9.1.9.8 | 9.1.9.8 |
| msrc | microsoft_dynamics_365_version_9.0 | — | — |
| msrc | microsoft_dynamics_365_version_9.1 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →An authenticated user running a specially crafted trusted solution package to execute arbitrary SQL commands should be monitored for anomalous SQL activity within the Dynamics CRM database. ↗
- →Monitor for privilege escalation to db_owner role within the Dynamics CRM database, which may indicate post-exploitation activity following malicious solution package execution. ↗
- ·Exploitation requires an authenticated user, limiting the attack surface to users with access to deploy trusted solution packages in Microsoft Dynamics 365 On-Premises. ↗
- ·As of the advisory, this vulnerability has not been publicly disclosed or exploited in the wild; exploitation is rated 'Less Likely' for both latest and older software releases. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
vendor_msrc·2022-04-12·CVSS 8.8
CVE-2022-23259 [HIGH] Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
FAQ: How could an attacker exploit this vulnerability?
An authenticated user could run a specially crafted trusted solution package to execute arbitrary SQL commands. From there the attacker could escalate and execute commands as db_owner within their Dynamics CRM database.
Microsoft Dynamics: Microsoft Dynamics
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely
Reference: https://www.microsoft.com/en-us/download/details.aspx?id=104010
Reference: https://support.microsoft.com/help/5012732
Reference: https://www.microsoft.com/en-us/downl
GHSA
GHSA-9v29-9c24-g7f5: Microsoft Dynamics 365 (on-premises) Remote Code Execution Vulnerability
ghsa_unreviewed·2022-04-16
CVE-2022-23259 [HIGH] CWE-269 GHSA-9v29-9c24-g7f5: Microsoft Dynamics 365 (on-premises) Remote Code Execution Vulnerability
Microsoft Dynamics 365 (on-premises) Remote Code Execution Vulnerability.
No detection rules found.
No public exploits indexed.
Qualys
April 2022 Patch Tuesday: Microsoft Releases 145 Vulnerabilities With 10 Critical; Adobe Releases 4 Advisories, 78 Vulnerabilities With 51 Critical.
blogs_qualys·2022-04-12·CVSS 8.8
[HIGH] April 2022 Patch Tuesday: Microsoft Releases 145 Vulnerabilities With 10 Critical; Adobe Releases 4 Advisories, 78 Vulnerabilities With 51 Critical.
## Table of Contents
Microsoft Patch Tuesday Summary
Notable Microsoft Vulnerabilities Patched
Notable Adobe Vulnerabilities Patched
About Qualys Patch Tuesday
Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
Rapid Response With Patch Management (PM)
Monthly Webinar Series: This Month in Vulnerabilities & Patches
Join the Webinar This Month in Vulnerabilities & Patches
Contributor
## Microsoft Patch Tuesday Summary
Microsoft has fixed 145 vulnerabilities, including 17 Microsoft Edge vulnerabilities, in the April 2022 update, with ten classified as critical as they allow Remote Code Execution (RCE). This month’s Patch Tuesday release includes fixes for two zero-day vulnerabilities as well, one known to be actively exploited ( CVE-2022-
Qualys
April 2022 Patch Tuesday: Microsoft Releases 145 Vulnerabilities With 10 Critical; Adobe Releases 4 Advisories, 78 Vulnerabilities With 51 Critical. | Qualys
blogs_qualys·2022-04-12·CVSS 8.8
[HIGH] April 2022 Patch Tuesday: Microsoft Releases 145 Vulnerabilities With 10 Critical; Adobe Releases 4 Advisories, 78 Vulnerabilities With 51 Critical. | Qualys
#### Table of Contents
- Microsoft Patch Tuesday Summary
- Notable Microsoft Vulnerabilities Patched
- Notable Adobe Vulnerabilities Patched
- About Qualys Patch Tuesday
- Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
- Rapid Response With Patch Management (PM)
- Monthly Webinar Series: This Month in Vulnerabilities & Patches
- Join the Webinar This Month in Vulnerabilities & Patches
- Contributor
## Microsoft Patch Tuesday Summary
Microsoft has fixed 145 vulnerabilities, including 17 Microsoft Edge vulnerabilities, in the April 2022 update, with ten classified as critical as they allow Remote Code Execution (RCE). This month’s Patch Tuesday release includes fixes for two zero-day vulnerabilities as well, one known to be actively exploited
Crowdstrike
April 2022 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] April 2022 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
2022-04-15
Published