CVE-2023-38167

CVSS 3.1 Score 7.2 of 10 (high)

Details

Published Aug 8, 2023
Updated: Jan 1, 2025
CWE ID 284

Summary

CVE-2023-38167 is a newly disclosed vulnerability affecting Microsoft Dynamics 365 Business Central. This Elevation of Privilege (EoP) issue allows an attacker to gain elevated permissions, potentially leading to unauthorized modifications or access to sensitive data. Successful exploitation of this vulnerability requires an attacker to have valid login credentials and manipulate specific functions within the affected application. Microsoft has released a security update to mitigate this issue, and users are strongly encouraged to apply it as soon as possible to protect their systems.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share