Impact
Improper handling of untrusted data during deserialization in Microsoft Dynamics 365 (on-premises) allows an attacker with authorized access to send crafted payloads that result in remote code execution. The attacker can run arbitrary code with the privileges of the service process, potentially compromising confidentiality, integrity, and availability of the entire system. The flaw is a classic deserialization of untrusted data vulnerability, classified as CWE-502.
Affected Systems
Microsoft Dynamics 365 on-premises version 9.1.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. No EPSS score is present, so current exploitation probability cannot be quantified. The vulnerability is not listed in CISA KEV, implying no publicly confirmed exploitation. Attack requires an authorized attacker with network access able to supply serialized data, so the vector is limited to insiders or users with some privileged access. With no public exploit, risk depends largely on whether the vulnerable deserialization endpoint is exposed and on the attacker's privileges.
OpenCVE Enrichment