Rewterz
Rewterz Threat Advisory – CVE-2023-23395 – Microsoft SharePoint Vulnerability
March 16, 2023
Rewterz
Rewterz Threat Advisory – CVE-2023-23389 – Microsoft Defender Vulnerability
March 16, 2023

Rewterz Threat Advisory – Multiple Microsoft Dynamics 365 Vulnerabilities

Severity

Medium

Analysis Summary

CVE-2023-24921 CVSS:4.1

Microsoft Dynamics 365 (on-premises) is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote authenticated attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim’s Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.

CVE-2023-24919 CVSS:5.4

Microsoft Dynamics 365 (on-premises) is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote authenticated attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim’s Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.

CVE-2023-24891 CVSS:5.4

Microsoft Dynamics 365 (on-premises) is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote authenticated attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim’s Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.

CVE-2023-24922 CVSS:6.5

Microsoft Dynamics 365 could allow a remote authenticated attacker to obtain sensitive information. By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain sensitive information from an error message and then use this information to launch further attacks against the affected system.

CVE-2023-24920 CVSS:5.4

Microsoft Dynamics 365 (on-premises) is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote authenticated attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim’s Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.

CVE-2023-24879 CVSS:5.4

Microsoft Dynamics 365 (on-premises) is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote authenticated attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim’s Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.

Impact

  • Cross-Site Scripting
  • Information Disclosure

Indicators Of Compromise

CVE

  • CVE-2023-24921
  • CVE-2023-24919
  • CVE-2023-24891
  • CVE-2023-24922
  • CVE-2023-24920
  • CVE-2023-24879

Affected Vendors

Microsoft

Affected Products

  • Microsoft Dynamics 365 Customer Engagement 9.0
  • Microsoft Dynamics 365 Customer Engagement 9.1

Remediation

Use Microsoft Automatic Update to apply the appropriate patch for your system, or the Microsoft Security Update Guide to search for available patches.

CVE-2023-24921

CVE-2023-24919

CVE-2023-24891

CVE-2023-24922

CVE-2023-24920

CVE-2023-24879