6.5
CVE-2023-35389
- EPSS 0.75%
- Veröffentlicht 08.08.2023 18:15:13
- Zuletzt bearbeitet 10.08.2026 16:18:28
- Erkennungen
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Dynamics 365 SwEdition on-premises Version >= 9.0 < 9.0.47.08
Microsoft ≫ Dynamics 365 SwEdition on-premises Version >= 9.1 < 9.1.18.22
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.75% | 0.516 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Microsoft | 6.5 | 2.3 | 3.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
|
CWE-611 Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-35389