CVE-2022-41127: Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability
Published Dec 13, 2022
·Updated
Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability
Affected Software
23 affected componentsFixes available
Microsoft Dynamics 365 Business Central Spring 2019 Update
Microsoft Dynamics 365 Business Central 2022 Release Wave 1
Microsoft Dynamics 365 Business Central=2019-release_wave_2
Microsoft Dynamics 365 Business Central=2019-spring_update
Microsoft Dynamics 365 Business Central=2020-release_wave_1
Microsoft Dynamics 365 Business Central=2020-release_wave_2
Microsoft Dynamics 365 Business Central=2021-release_wave_1
Microsoft Dynamics 365 Business Central=2021-release_wave_2
Microsoft Dynamics 365 Business Central=2022-release_wave_1
Microsoft Dynamics NAV=2016
Microsoft Dynamics NAV=2017
Microsoft Dynamics NAV=2018
Microsoft Dynamics 365 Business Central 2020 Release Wave 1
Microsoft Dynamics 365 Business Central 2020 Release Wave 2
Microsoft Dynamics 365 Business Central 2019 Release Wave 2 (On-Premise)
Microsoft Dynamics 365 Business Central 2022 Release Wave 2
Microsoft Dynamics 365 Business Central 2021 Release Wave 1
Microsoft Dynamics 365 Business Central 2021 Release Wave 2
Microsoft Dynamics NAV 2016
Microsoft Dynamics NAV 2013 R2
Microsoft Dynamics NAV 2017
Microsoft Dynamics NAV 2018
Microsoft Dynamics NAV 2015
Event History
Dec 13, 2022
CVE Published
12:00 AM
Data Sourced
12:00 AM
DescriptionSeverity
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-41127?
CVE-2022-41127 has been rated as critical due to its potential for remote code execution.
2
How do I fix CVE-2022-41127?
To remediate CVE-2022-41127, ensure you apply the security updates provided by Microsoft for the affected Dynamics products.
3
Which products are affected by CVE-2022-41127?
CVE-2022-41127 affects several versions of Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central.
4
What types of attacks can exploit CVE-2022-41127?
CVE-2022-41127 can be exploited by attackers to execute arbitrary code remotely on vulnerable systems.
5
Is there a workaround for CVE-2022-41127?
Currently, applying the available patches is the recommended solution as there are no known effective workarounds for CVE-2022-41127.