Lucene search

K
kasperskyKaspersky LabKLA11999
HistoryNov 10, 2020 - 12:00 a.m.

KLA11999 Multiple vulnerabilities in Microsoft Dynamics

2020-11-1000:00:00
Kaspersky Lab
threats.kaspersky.com
14
microsoft dynamics
cross-site scripting
versions 7.0 8.2 9.0

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

AI Score

5

Confidence

High

EPSS

0.001

Percentile

20.3%

Multiple vulnerabilities was found in Microsoft Dynamics. Malicious users can exploit this vulnerability to perform cross-site scripting attack.

Original advisories

CVE-2020-17018

CVE-2020-17005

CVE-2020-17006

CVE-2020-17021

Related products

Microsoft-Dynamics-365

CVE list

CVE-2020-17018 high

CVE-2020-17005 high

CVE-2020-17006 high

CVE-2020-17021 high

KB list

4584612

4577009

4584611

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Impacts

  • XSS/CSS

Cross site scripting. Exploitation of vulnerabilities with this impact can lead to partial interception of information transmitted between user and site.

Affected Products

  • Microsoft Dynamics 365 (on-premises) version 9.0Microsoft Dynamics CRM 2015 (on-premises) version 7.0Microsoft Dynamics 365 (on-premises) version 8.2

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

AI Score

5

Confidence

High

EPSS

0.001

Percentile

20.3%