Executive brief
Microsoft Dynamics 365 (on-premises) is a business application suite used for managing customer relationships and enterprise resources. A critical vulnerability allows an authorized user to inject and execute malicious code on the server over the network. This could lead to a complete takeover of the system, unauthorized access to sensitive business data, and disruption of corporate operations.
Technical details
A code injection vulnerability (CWE-94) exists in Microsoft Dynamics 365 (on-premises) due to improper control of the generation of code. An attacker with low-privileged credentials can exploit this flaw over a network without user interaction. Successful exploitation allows for arbitrary code execution with a 'Changed' scope (S:C), meaning the attacker can potentially impact components beyond the Dynamics 365 application itself. Microsoft has released security updates to address this issue; administrators should refer to the Microsoft Security Update Guide for specific patch details.
Affected products
- Microsoft Dynamics 365 (on-premises)
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory