Executive brief
Microsoft Dynamics 365 is an enterprise resource planning and customer relationship management platform used by organizations to manage business operations and customer interactions. A deserialization vulnerability allows an authorized network user to execute arbitrary code on systems running the affected product, potentially leading to complete system compromise, data theft, and operational disruption.
Technical details
The vulnerability stems from unsafe deserialization of untrusted data in Microsoft Dynamics 365. An authenticated attacker with network access can craft malicious serialized objects that, when deserialized by the application, trigger remote code execution. The attack requires valid credentials (authorization), but once authenticated, the attacker gains the ability to execute arbitrary code with the privileges of the Dynamics 365 service. No user interaction or additional exploitation steps are needed beyond sending the malicious payload over the network. Microsoft has addressed this issue with security updates.
Affected products
- Microsoft Dynamics 365
Timeline
- 2026-09-08: disclosed