CVE-2025-62206
published 2025-11-11CVE-2025-62206: Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over…
PriorityP336medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.90%
55.6th percentile
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | dynamics_365 | >= 9.1 < 9.1.41.07 | 9.1.41.07 |
| microsoft | microsoft_dynamics_365_version_9.1 | >= 9.0 < 9.1.41.07 | 9.1.41.07 |
| msrc | microsoft_dynamics_365_version_9.1 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
vendor_msrc6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cwwr-cv2h-5hmx: Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose informa
ghsa_unreviewed·2025-11-11
CVE-2025-62206 [MEDIUM] CWE-200 GHSA-cwwr-cv2h-5hmx: Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose informa
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network.
Microsoft
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
vendor_msrc·2025-11-11·CVSS 6.5
CVE-2025-62206 [MEDIUM] CWE-200 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
Description: Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network.
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is sensitive information.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
The user would have to click on a specially crafted URL to be compromised by the attacker, and navigate to a malicious site where malicious code would execute a series of specially crafted queries.
Microsoft Dynamics 36
No detection rules found.
No public exploits indexed.
2025-11-11
Published