CVE-2022-41127: Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability

Published Dec 13, 2022
·
Updated

Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability

Affected Software

23 affected componentsFixes available
Microsoft Dynamics 365 Business Central=2019-release_wave_2
Microsoft Dynamics 365 Business Central=2019-spring_update
Microsoft Dynamics 365 Business Central=2020-release_wave_1
Microsoft Dynamics 365 Business Central=2020-release_wave_2
Microsoft Dynamics 365 Business Central=2021-release_wave_1
Microsoft Dynamics 365 Business Central=2021-release_wave_2
Microsoft Dynamics 365 Business Central=2022-release_wave_1
Microsoft Dynamics NAV=2016
Microsoft Dynamics NAV=2017
Microsoft Dynamics NAV=2018
Microsoft Dynamics 365 Business Central 2020 Release Wave 1<16.0.35120
16.0.35120
Microsoft Dynamics 365 Business Central 2020 Release Wave 2<17.0.38061
17.0.38061
Microsoft Dynamics 365 Business Central Spring 2019 Update<14.0.49494
14.0.49494
Microsoft Dynamics NAV 2016<Build 52203
Build 52203
Microsoft Dynamics NAV 2015<52204
52204
Microsoft Dynamics 365 Business Central 2019 Release Wave 2 (On-Premise)<15.0.48426
15.0.48426
Microsoft Dynamics NAV 2018<Build 49497
Build 49497
Microsoft Dynamics NAV 2017<Build 30712
Build 30712
Microsoft Dynamics 365 Business Central 2022 Release Wave 2<21.0.49984
21.0.49984
Microsoft Dynamics 365 Business Central 2021 Release Wave 1<18.0.46905
18.0.46905
Microsoft Dynamics NAV 2013 R2<52297
52297
Microsoft Dynamics 365 Business Central 2022 Release Wave 1<20.0.49947
20.0.49947
Microsoft Dynamics 365 Business Central 2021 Release Wave 2<19.0.49925
19.0.49925

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 16.0.35120Patch KB5010910
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 17.0.38061Patch KB5013420
  3. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 14.0.49494Patch KB5021669
  4. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in Build 49497Patch KB5021668
  5. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in Build 52203Patch KB5005293
  6. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 15.0.48426Patch KB5001733
  7. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 52204
  8. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in Build 30712Patch KB5010202
  9. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 18.0.46905Patch KB5019239
  10. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 21.0.49984Patch KB5021672
  11. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 52297
  12. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 20.0.49947Patch KB5021671
  13. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 19.0.49925Patch KB5021670

Event History

Dec 13, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via Microsoft·04:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·04:00 PM
Affected Software
Updated
via Microsoft·04:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2022-41127?

CVE-2022-41127 has been rated as critical due to its potential for remote code execution.

2

How do I fix CVE-2022-41127?

To remediate CVE-2022-41127, ensure you apply the security updates provided by Microsoft for the affected Dynamics products.

3

Which products are affected by CVE-2022-41127?

CVE-2022-41127 affects several versions of Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central.

4

What types of attacks can exploit CVE-2022-41127?

CVE-2022-41127 can be exploited by attackers to execute arbitrary code remotely on vulnerable systems.

5

Is there a workaround for CVE-2022-41127?

Currently, applying the available patches is the recommended solution as there are no known effective workarounds for CVE-2022-41127.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203