Vulnerabilities > CVE-2020-0905 - Unspecified vulnerability in Microsoft Dynamics 365 Business Central and Dynamics NAV

047910
CVSS 8.0 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
microsoft
nessus

Summary

An remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerability'.

Nessus

  • NASL familyWindows : Microsoft Bulletins
    NASL idSMB_NT_MS20_MAR_MICROSOFT_DYNAMICS_365_BC.NASL
    descriptionThe Microsoft Dynamics 365 Business Central install is missing a security update. It is, therefore, affected by a remote code execution vulnerability due to an issue with the Role-Tailored Client. An authenticated, remote attacker can exploit this to execute arbitrary commands or elevate privileges. Note that Nessus has not attempted to exploit this issue but has instead relied only on the application
    last seen2020-05-15
    modified2020-05-11
    plugin id136472
    published2020-05-11
    reporterThis script is Copyright (C) 2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/136472
    titleSecurity Updates for Microsoft Dynamics 365 Business Central (Mar 2020)
  • NASL familyWindows : Microsoft Bulletins
    NASL idSMB_NT_MS20_MAR_MICROSOFT_DYNAMICS_NAV.NASL
    descriptionThe Microsoft Dynamics NAV install is missing a security update. It is, therefore, affected by a remote code execution vulnerability due to an issue with the Role-Tailored Client. An authenticated, remote attacker can exploit this to execute arbitrary commands or elevate privileges. Note that Nessus has not attempted to exploit this issue but has instead relied only on the application
    last seen2020-05-15
    modified2020-05-11
    plugin id136473
    published2020-05-11
    reporterThis script is Copyright (C) 2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/136473
    titleSecurity Updates for Microsoft Dynamics NAV (Mar 2020)