Impact
The vulnerability in Microsoft Dynamics 365 Customer Engagement allows an attacker who already has authorized access to the application to inject and execute arbitrary code. This is a code injection flaw (CWE-94) that can be leveraged over a network connection, enabling the attacker to run malicious payloads with the privileges of the authenticated user and potentially access, modify, or delete data within the system.
Affected Systems
Microsoft Dynamics 365 Customer Engagement V9.1. No specific sub‑versions are listed, so any instance of this product that has not yet applied the vendor’s security update is potentially affected.
Risk and Exploitability
The CVSS score of 8.8 denotes high severity, and the absence of an EPSS score indicates that current evidence of exploitation is unknown, yet the flaw remains in the CISA KEV catalog as not listed. The likely attack vector is a network‑based attack requiring authorized credentials; consequently, the risk is substantial for organizations that have exposed Dynamics 365 to internal or external networks without additional controls.
OpenCVE Enrichment