CVE-2022-41066
published 2022-11-09CVE-2022-41066: Microsoft Business Central Information Disclosure Vulnerability
PriorityP417medium4.4CVSS 3.1
AVNACHPRHUINSUCHINAN
EPSS
1.07%
60.8th percentile
Microsoft Business Central Information Disclosure Vulnerability
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | dynamics_365_business_central_2019 | < 14.42.49347 | 14.42.49347 |
| microsoft | dynamics_365_business_central_2021 | <= 19.18.54872 | — |
| microsoft | dynamics_365_business_central_2022 | < 20.7.48483 | 20.7.48483 |
| microsoft | dynamics_365_business_central_2022 | >= 21.1.48638 < 21.1.48638 | 21.1.48638 |
| microsoft | dynamics_365_business_central_spring_2019_update | >= 14.0.0 < Application Build 14.42.49347, Platform Build 14.0 | Application Build 14.42.49347, Platform Build 14.0 |
| microsoft | dynamics_nav | — | — |
| microsoft | microsoft_dynamics_365_business_central_2021_release_wave_2 | >= 19.0.0 < Application Build 21.2.49990, Platform Build 21.0 | Application Build 21.2.49990, Platform Build 21.0 |
| microsoft | microsoft_dynamics_365_business_central_2022_release_wave_1 | >= 20.0.0 < Application Build 20.7.48483, Platform Build 20.0. | Application Build 20.7.48483, Platform Build 20.0. |
| microsoft | microsoft_dynamics_365_business_central_2022_release_wave_2 | >= 21.0.0 < Application Build 21.1.48638, Platform Build 21.0. | Application Build 21.1.48638, Platform Build 21.0. |
| microsoft | microsoft_dynamics_nav_2018 | >= 1.0 < 49345 | 49345 |
| msrc | dynamics_365_business_central_spring_2019_update | — | — |
| msrc | microsoft_dynamics_365_business_central_2021_release_wave_2 | — | — |
| msrc | microsoft_dynamics_365_business_central_2022_release_wave_1 | — | — |
| msrc | microsoft_dynamics_365_business_central_2022_release_wave_2 | — | — |
| msrc | microsoft_dynamics_nav_2018 | — | — |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
vendor_msrc4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-33m5-rgm6-r8x3: Microsoft Business Central Information Disclosure Vulnerability
ghsa_unreviewed·2022-11-10
CVE-2022-41066 [MEDIUM] GHSA-33m5-rgm6-r8x3: Microsoft Business Central Information Disclosure Vulnerability
Microsoft Business Central Information Disclosure Vulnerability.
Microsoft
Microsoft Business Central Information Disclosure Vulnerability
vendor_msrc·2022-11-08·CVSS 4.4
CVE-2022-41066 [MEDIUM] Microsoft Business Central Information Disclosure Vulnerability
Microsoft Business Central Information Disclosure Vulnerability
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to gather information specific to the environment of the targeted component.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to take additional actions prior to exploitation to prepare the target environment.
FAQ: According to the CVSS metric, privileges required is high (PR:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to compromise admin cr
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-11-09
Published