CVE-2023-38167
CVSS 3.1 Score 7.2 of 10 (high)
Details
Summary
CVE-2023-38167 is a newly disclosed vulnerability affecting Microsoft Dynamics 365 Business Central. This Elevation of Privilege (EoP) issue allows an attacker to gain elevated permissions, potentially leading to unauthorized modifications or access to sensitive data. Successful exploitation of this vulnerability requires an attacker to have valid login credentials and manipulate specific functions within the affected application. Microsoft has released a security update to mitigate this issue, and users are strongly encouraged to apply it as soon as possible to protect their systems.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Microsoft