Endpoint Vulnerability

Microsoft Dynamics On-Premise Security Feature Bypass

Description

A security feature bypass vulnerability exists in Dynamics On Premise. An attacker who exploited the vulnerability could send attachment types that are blocked by the email attachment system. To exploit the vulnerability, an attacker would need to capture and edit the POST request to include a special character in the extension. The update addresses the vulnerability by blocking files with the special character in the file extension.

Affected Products

Microsoft Dynamics 365 (on-premises) version 9.0,Microsoft Dynamics CRM 2015 (on-premises) version 7.0,Microsoft Dynamics 365 (on-premises) version 8.2

References

CVE-2019-1008,