Executive brief
Microsoft Dynamics 365 Customer Voice, a feedback management service used to create and track customer surveys, contains a critical security vulnerability. An attacker could exploit this flaw to perform spoofing attacks, potentially leading to the theft of sensitive customer data or unauthorized actions within the application. This could result in significant reputational damage and the compromise of customer-facing communication channels.
Technical details
A cross-site scripting (XSS) vulnerability exists in Microsoft Dynamics 365 Customer Voice due to improper neutralization of input during web page generation (CWE-79). An unauthenticated attacker can exploit this over the network by inducing a user to interact with a malicious link or crafted content. Successful exploitation allows the attacker to perform spoofing, bypass security boundaries (Scope: Changed), and achieve high impact on confidentiality and integrity. The vulnerability is rated critical with a CVSS score of 9.3, reflecting its potential for significant data exposure without requiring administrative privileges.
Affected products
- Microsoft Dynamics 365 Customer Voice All versions
Timeline
- 2026-07-09: advisory: Initial advisory published by Microsoft and NVD.