First published: Wed Nov 14 2018(Updated: )
A remote code execution vulnerability exists in Microsoft Dynamics 365 (on-premises) version 8 when the server fails to properly sanitize web requests to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Remote Code Execution Vulnerability." This affects Microsoft Dynamics 365.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Dynamics 365 (on-premises) | >=8.0<8.2.3.0003 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8609 is classified as a critical vulnerability due to its potential for remote code execution.
CVE-2018-8609 affects Microsoft Dynamics 365 (on-premises) version 8 by allowing remote attackers to execute arbitrary code on the server.
To fix CVE-2018-8609, you should apply the latest security updates provided by Microsoft for Dynamics 365 (on-premises) version 8.
Yes, CVE-2018-8609 specifically affects Microsoft Dynamics 365 (on-premises) versions 8.0 to 8.2.3.0003.
CVE-2018-8609 is caused by improper sanitization of web requests sent to the Microsoft Dynamics 365 server.