Microsoft Dynamics On-Premise CVE-2019-1008 Security Feature Bypass Vulnerability

description-logoDescription

A security feature bypass vulnerability exists in Dynamics On Premise. An attacker who exploited the vulnerability could send attachment types that are blocked by the email attachment system. To exploit the vulnerability, an attacker would need to capture and edit the POST request to include a special character in the extension. The update addresses the vulnerability by blocking files with the special character in the file extension.

affected-products-logoAffected Applications

Microsoft Dynamics 365 (on-premises) version 9.0
Microsoft Dynamics CRM 2015 (on-premises) version 7.0
Microsoft Dynamics 365 (on-premises) version 8.2

CVE References

CVE-2019-1008