Microsoft Dynamics Unified Service Desk RCE Vulnerability
CVE-2023-21778 Published on February 14, 2023

Microsoft Dynamics Unified Service Desk Remote Code Execution Vulnerability
Microsoft Dynamics Unified Service Desk Remote Code Execution Vulnerability

Vendor Advisory NVD

Weakness Type

What is a Command Injection Vulnerability?

The software constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

CVE-2023-21778 has been classified to as a Command Injection vulnerability or weakness.


Products Associated with CVE-2023-21778

Want to know whenever a new CVE is published for Microsoft Dynamics 365? stack.watch will email you.

 

Affected Versions

Microsoft Dynamics 365 Unified Service Desk:

Exploit Probability

EPSS
1.49%
Percentile
80.84%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.