Impact
Deserialization of untrusted data in Microsoft Dynamics NAV allows an attacker to execute arbitrary code over a network. This flaw is a CWE‑502 type vulnerability involving unsafe deserialization of untrusted binary data. Successful exploitation would grant the attacker immediate confidentiality and integrity compromise, enabling full control of the application and underlying host.
Affected Systems
Microsoft Dynamics NAV 2018 is confirmed vulnerable; this analysis infers that the flaw affects installations which expose the deserialization endpoint to unauthenticated network traffic.
Risk and Exploitability
The CVSS score of 9.8 and an EPSS score of 1% indicate a severe risk and a very low probability of exploitation. The CVE is not listed in the CISA KEV catalog. This analysis infers that the attack vector is a remote, unauthenticated network attack that targets the deserialization mechanism; the attacker must be able to send crafted data to the vulnerable endpoint to trigger code execution.
OpenCVE Enrichment