cbcvebase.
CVE-2022-35805
published 2022-09-13

CVE-2022-35805: Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability

PriorityP356high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.29%
81.1th percentile
Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability

Affected

6 ranges
VendorProductVersion rangeFixed in
microsoftdynamics_365
microsoftdynamics_365
microsoftmicrosoft_dynamics_crm_9.0>= 9.0.0 < 9.0.40.59.0.40.5
microsoftmicrosoft_dynamics_crm_9.1>= 9.1.0 < 9.1.12.179.1.12.17
msrcmicrosoft_dynamics_crm_9.0
msrcmicrosoft_dynamics_crm_9.1

Detection & IOCsextracted from sources · hover to see the quote

  • Attacker must be authenticated (low privilege) and executes a specially crafted trusted solution package to trigger arbitrary SQL command execution within Dynamics CRM database
  • Monitor for unexpected SQL command execution or privilege escalation to db_owner role originating from Dynamics CRM service accounts or solution import processes
  • ·Exploitation requires authentication; unauthenticated attackers cannot exploit this vulnerability. Scope is limited to on-premises Dynamics CRM deployments only.
  • ·As of advisory publication, the vulnerability had not been publicly disclosed or exploited in the wild, reducing immediate risk but patching is still required.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.