Impact
Improper handling of access control in Microsoft Dynamics 365 on‑premises allows an attacker with existing authorization to raise their privileges across the network. The flaw stems from a missing access control mechanism (CWE‑755) that fails to validate adequate permissions before permitting higher-level actions. Consequently, the attacker can gain elevated access, potentially controlling system functions that should remain restricted, thereby raising confidentiality and integrity risks.
Affected Systems
Microsoft Dynamics 365 (on‑premises) version 9.1 is affected.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. The EPSS score is 0.0063 and the vulnerability is not listed in the CISA KEV catalog, the risk remains significant because the attack vector requires an authorized user with existing access, which is a realistic scenario in many environments. Exploitation would involve the attacker leveraging the application's insufficient permission checks to elevate privileges over the network, resulting in potential system compromise.
OpenCVE Enrichment