Lucene search

K
kasperskyKaspersky LabKLA50320
HistoryJun 13, 2023 - 12:00 a.m.

KLA50320 Multiple vulnerabilities in Microsoft Dynamics

2023-06-1300:00:00
Kaspersky Lab
threats.kaspersky.com
11
microsoft dynamics
ui spoofing
dynamics 365
power apps
sui
cve-2023-32024
cve-2023-24896
updates

5.4 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

5.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

20.7%

Multiple vulnerabilities were found in Microsoft Dynamics. Malicious users can exploit these vulnerabilities to spoof user interface.

Below is a complete list of vulnerabilities:

  1. A spoofing vulnerability in Microsoft Power Apps can be exploited remotely to spoof user interface.
  2. A spoofing vulnerability in Dynamics 365 Finance can be exploited remotely to spoof user interface.

Original advisories

CVE-2023-32024

CVE-2023-24896

Related products

Microsoft-Dynamics-365

CVE list

CVE-2023-32024 warning

CVE-2023-24896 high

KB list

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Impacts

  • SUI

Spoof user interface. Exploitation of vulnerabilities with this impact can lead to changes in user interface to beguile user into inaccurate behavior.

Affected Products

  • Dynamics 365 for Finance and OperationsMicrosoft Power Apps

5.4 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

5.4 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

20.7%