CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-42833

CVSS 9.1v3.1pub. 2026-05-12upd. 2026-06-01

Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.

🤖 AI Analysis
How it works

The flaw consists of improper control of code generation (CWE-250 — execution with excessive privileges) in the Microsoft Dynamics 365 component in the on-premises version. An attacker with privileges in the system can supply specially crafted input data that is interpreted and executed as code on the server side. The attack vector is network-based, requires no user interaction, and the scope of attack extends beyond the component itself (Scope: Changed), indicating the possibility of impact on other system resources.

Impact

Successful exploitation of this vulnerability may allow an attacker to execute arbitrary code on the server, leading to complete compromise of confidentiality, integrity, and availability of the system, and potentially to takeover of control over other related infrastructure resources.

Mitigation & patch

Patches available from the vendor should be applied in accordance with references published at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42833

Who is affected

Microsoft Dynamics 365 in on-premises version — specific versions indicated in vendor references (MSRC)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Microsoft Dynamics 365

    APP
    Microsoft
    9.1 – 9.1.45.11 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-47647CRITICAL9.9PL ✓same product

Privilege escalation w Microsoft Dynamics 365 przez niewłaściwą kontrolę dostępu

CVE-2026-42898CRITICAL9.9PL ✓same product

Code injection w Microsoft Dynamics 365 (on-premises) umożliwiający RCE

CVE-2026-32210CRITICAL9.3PL ✓same product

SSRF w Microsoft Dynamics 365 umożliwia spoofing sieciowy

CVE-2024-38182CRITICAL9.0PL ✓same product

Słabe uwierzytelnianie w Microsoft Dynamics 365 umożliwia privilege escalation

CVE-2026-65815HIGH8.8same product

Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to exe...