Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2024-30061: Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability

According to the CVSS metric, user interaction is required (UI:R) and privileges required is low (PR:L). What does that mean for this vulnerability?

An authorized attacker must be on the network to monitor domain network traffic (PR:L) while monitoring for user (UI:R) generated network traffic, or alternatively that attacker convinces an authenticated user to execute a malicious script, as a step to exploit this vulnerability.

Microsoft Security Response Center
#vulnerability#microsoft#auth#Microsoft Dynamics#Security Vulnerability

Microsoft Security Response Center: Latest News

CVE-2024-49060: Azure Stack HCI Elevation of Privilege Vulnerability