CVE-2025-21177: Microsoft Dynamics 365 Sales Elevation of Privilege Vulnerability
Published Feb 6, 2025
·Updated
Microsoft Dynamics 365 Sales Elevation of Privilege Vulnerability
Other sources
Server-side request forgery (ssrf) in Microsoft Dynamics 365 Sales allows an authorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
2 affected components
Microsoft Dynamics 365 Sales
Microsoft Dynamics 365 Sales
Event History
Feb 6, 2025
CVE Published
via Microsoft·08:00 AM
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
CVE Published
via MITRE·10:41 PM
Data Sourced
via MITRE·10:41 PM
DescriptionSeverity
Feb 11, 2025
News Published
via Dark Reading·09:55 PM
News Published
via Dark Reading·10:24 PM
Feb 12, 2025
News Published
via The Register·02:58 AM
Feb 16, 2025
News Published
via The Register·03:01 AM
Known Exploited
03:01 AM
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2025-21177?
CVE-2025-21177 is classified as an elevation of privilege vulnerability.
2
How do I fix CVE-2025-21177?
To mitigate CVE-2025-21177, ensure that your Microsoft Dynamics 365 Sales is updated to the latest security patch provided by Microsoft.
3
Who is affected by CVE-2025-21177?
CVE-2025-21177 affects users of Microsoft Dynamics 365 Sales with authorized access.
4
What type of vulnerability is CVE-2025-21177?
CVE-2025-21177 is a Server-Side Request Forgery (SSRF) vulnerability.
5
What can an attacker do with CVE-2025-21177?
An attacker exploiting CVE-2025-21177 can elevate privileges over a network within Microsoft Dynamics 365 Sales.