CVE-2023-21778
published 2023-02-14CVE-2023-21778: Microsoft Dynamics Unified Service Desk Remote Code Execution Vulnerability
PriorityP344high8CVSS 3.1
AVNACHPRLUIRSCCHIHAH
EPSS
0.97%
57.7th percentile
Microsoft Dynamics Unified Service Desk Remote Code Execution Vulnerability
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | dynamics_365 | < 4.2.0.51 | 4.2.0.51 |
| microsoft | microsoft_dynamics_365_unified_service_desk | >= 4.2.0 < 4.2.0.51 | 4.2.0.51 |
| msrc | microsoft_dynamics_365_unified_service_desk | — | — |
CVSS provenance
nvdv3.18.0HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
vendor_msrc8.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9f7p-38pj-28rv: Microsoft Dynamics Unified Service Desk Remote Code Execution Vulnerability
ghsa_unreviewed·2023-02-14
CVE-2023-21778 [HIGH] GHSA-9f7p-38pj-28rv: Microsoft Dynamics Unified Service Desk Remote Code Execution Vulnerability
Microsoft Dynamics Unified Service Desk Remote Code Execution Vulnerability
Microsoft
Microsoft Dynamics Unified Service Desk Remote Code Execution Vulnerability
vendor_msrc·2023-02-14·CVSS 8.0
CVE-2023-21778 [HIGH] CWE-77 Microsoft Dynamics Unified Service Desk Remote Code Execution Vulnerability
Microsoft Dynamics Unified Service Desk Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?
In this case, the attack is carried over the webpage but it compromises the web server running the page. In addition, the attacker might be able to call victim's local files in the Resources directory and execute Windows commands that are outside of the Dynamics application.
FAQ: According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?
The attacker must be authenticated to be able to exploit this vulnerability.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerabili
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-02-14
Published