7.3

CVE-2024-35248

Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability

Data is provided by the National Vulnerability Database (NVD)
MicrosoftDynamics 365 Business Central Version2023 Updaterelease_wave_1
MicrosoftDynamics 365 Business Central Version2023 Updaterelease_wave_2
MicrosoftDynamics 365 Business Central Version2024 Updaterelease_wave_1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.7% 0.816
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
secure@microsoft.com 7.3 3.9 3.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CWE-1390 Weak Authentication

The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.

CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.