Microsoft Dynamics
CVE-2019-1008 — Microsoft Dynamics On-Premise Security Feature Bypass
Executive Summary
A security feature bypass vulnerability exists in Dynamics On Premise. An attacker who exploited the vulnerability could send attachment types that are blocked by the email attachment system. To exploit the vulnerability, an attacker would need to capture and edit the POST request to include a special character in the extension. The update addresses the vulnerability by blocking files with the special character in the file extension.
Overview
Important
MS Severity
Not Exploited
MS Exploit Status
Less Likely
MS Exploit Likelihood
EPSS Score
0.02762
probability of exploitation in the next 30 days
0.8437 percentile - updated 2026-06-20
View on FIRST.org
Affected Products
3 affected products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Microsoft Dynamics 365 (on-premises) version 8.2 | 4494412 (Security Update) |
Important | Security Feature Bypass | Maybe |
| Microsoft Dynamics 365 (on-premises) version 9.0 | 4498363 (Security Update) |
Important | Security Feature Bypass | Maybe |
| Microsoft Dynamics CRM 2015 (on-premises) version 7.0 | 4499386 (Security Update) |
Important | Security Feature Bypass | Maybe |
Patches
3 patches
| Article | Type | Restart |
|---|---|---|
4494412 |
Security Update | Maybe |
4498363 |
Security Update | Maybe |
4499386 |
Security Update | Maybe |
Known Exploits
No known exploits have been linked for this CVE yet. When available, exploit references will be sourced from public repositories and may be unverified, incomplete, or non-functional. Always review code carefully before use in any environment.
Acknowledgments
References
On This Page