Input validation error in Microsoft Dynamics 365 - CVE-2020-16862
Published: September 8, 2020
Microsoft Dynamics 365
Microsoft
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to the server fails to properly sanitize web requests to an affected Dynamics server. A remote authenticated attacker can send specially crafted requests to the affected system and execute arbitrary code.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.