CVE-2022-34700
published 2022-09-13CVE-2022-34700: Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability
PriorityP358high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
3.24%
86.9th percentile
Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | dynamics_365 | — | — |
| microsoft | dynamics_365 | — | — |
| microsoft | microsoft_dynamics_crm_9.0 | >= 9.0.0 < 9.0.40.5 | 9.0.40.5 |
| microsoft | microsoft_dynamics_crm_9.1 | >= 9.1.0 < 9.1.12.17 | 9.1.12.17 |
| msrc | microsoft_dynamics_crm_9.0 | — | — |
| msrc | microsoft_dynamics_crm_9.1 | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3rrx-r28h-qh3c: Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability
ghsa_unreviewed·2022-09-14·CVSS 8.8
CVE-2022-35805 [HIGH] GHSA-3rrx-r28h-qh3c: Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability
Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-34700.
GHSA
GHSA-5fxf-jjpm-w4vm: Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability
ghsa_unreviewed·2022-09-14·CVSS 8.8
CVE-2022-34700 [HIGH] CWE-89 GHSA-5fxf-jjpm-w4vm: Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability
Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-35805.
Microsoft
Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability
vendor_msrc·2022-09-13·CVSS 8.8
CVE-2022-34700 [HIGH] Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability
Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability
FAQ: How could an attacker exploit this vulnerability?
An authenticated user could run a specially crafted trusted solution package to execute arbitrary SQL commands. From there the attacker could escalate and execute commands as db_owner within their Dynamics CRM database.
FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?
The attacker must be authenticated to be able to exploit this vulnerability.
Microsoft Dynamics: Microsoft Dynamics
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitatio
No detection rules found.
No public exploits indexed.
Krebs
Wormable Flaw, 0days Lead Sept. 2022 Patch Tuesday
blogs_krebs·2022-09-14·CVSS 7.8
[HIGH] Wormable Flaw, 0days Lead Sept. 2022 Patch Tuesday
This month’s Patch Tuesday offers a little something for everyone, including security updates for a zero-day flaw in Microsoft Windows that is under active attack, and another Windows weakness experts say could be used to power a fast-spreading computer worm. Also, Apple has also quashed a pair of zero-day bugs affecting certain macOS and iOS users, and released iOS 16 , which offers a new privacy and security feature called “ Lockdown Mode .” And Adobe axed 63 vulnerabilities in a range of products.
Microsoft today released software patches to plug at least 64 security holes in Windows and related products. Worst in terms of outright scariness is CVE-2022-37969 , which is a “privilege escalation” weakness in the Windows Common Log File System Driver that allows attackers to gain SYSTEM-l
Talos
Microsoft Patch Tuesday for September 2022 — Snort rules and prominent vulnerabilities
blogs_talos·2022-09-13·CVSS 8.8
[HIGH] Microsoft Patch Tuesday for September 2022 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for September 2022 — Snort rules and prominent vulnerabilities
Microsoft released its monthly security update Tuesday, disclosing 64 vulnerabilities across the company’s hardware and software line, a sharp decline from the record number of issues Microsoft disclosed last month.
September's security update features five critical vulnerabilities, 10 fewer than were included in last month’s Patch Tuesday. There are two moderate-severity vulnerabilities in this release and a low-security issue that’s already been patched as a part of a recent Google Chromium update. The remainder is considered “important.”
The most serious vulnerability exists in several versions of Windows Server and Windows 10 that could allow an attacker to gain the ability to execute remote co
Talos
Microsoft Patch Tuesday for September 2022 — Snort rules and prominent vulnerabilities
blogs_talos·2022-09-13·CVSS 8.8
[HIGH] Microsoft Patch Tuesday for September 2022 — Snort rules and prominent vulnerabilities
Microsoft released its monthly security update Tuesday, disclosing 64 vulnerabilities across the company’s hardware and software line, a sharp decline from the record number of issues Microsoft disclosed last month.
September's security update features five critical vulnerabilities, 10 fewer than were included in last month’s Patch Tuesday. There are two moderate-severity vulnerabilities in this release and a low-security issue that’s already been patched as a part of a recent Google Chromium update. The remainder is considered “important.”
The most serious vulnerability exists in several versions of Windows Server and Windows 10 that could allow an attacker to gain the ability to execute remote code (RCE) by sending a singular, specially crafted IPv6 packet to a Windows node where IPSec
Krebs
Wormable Flaw, 0days Lead Sept. 2022 Patch Tuesday
blogs_krebs·2022-09-13·CVSS 7.8
[HIGH] Wormable Flaw, 0days Lead Sept. 2022 Patch Tuesday
This month’s Patch Tuesday offers a little something for everyone, including security updates for a zero-day flaw in Microsoft Windows that is under active attack, and another Windows weakness experts say could be used to power a fast-spreading computer worm. Also, Apple has also quashed a pair of zero-day bugs affecting certain macOS and iOS users, and released iOS 16, which offers a new privacy and security feature called “Lockdown Mode.” And Adobe axed 63 vulnerabilities in a range of products.
Microsoft today released software patches to plug at least 64 security holes in Windows and related products. Worst in terms of outright scariness is CVE-2022-37969, which is a “privilege escalation” weakness in the Windows Common Log File System Driver that allows attackers to gain SYSTEM-level
Crowdstrike
September Patch Tuesday 2022: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] September Patch Tuesday 2022: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
2022-09-13
Published