Important EPSS 0.02762 2019-05 archive

Executive Summary

A security feature bypass vulnerability exists in Dynamics On Premise. An attacker who exploited the vulnerability could send attachment types that are blocked by the email attachment system. To exploit the vulnerability, an attacker would need to capture and edit the POST request to include a special character in the extension. The update addresses the vulnerability by blocking files with the special character in the file extension.

Overview

Important
MS Severity
Not Exploited
MS Exploit Status
Less Likely
MS Exploit Likelihood
Category Security Feature Bypass
Released May 14 2019
Last Updated May 14 2019
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.02762 — 0.8437 percentile

EPSS Score

0.02762
probability of exploitation in the next 30 days
0.8437 percentile - updated 2026-06-20
View on FIRST.org

Affected Products

3 affected products
Product KB Article Severity Impact Restart Required
Microsoft Dynamics 365 (on-premises) version 8.2 4494412 (Security Update) Important Security Feature Bypass Maybe
Microsoft Dynamics 365 (on-premises) version 9.0 4498363 (Security Update) Important Security Feature Bypass Maybe
Microsoft Dynamics CRM 2015 (on-premises) version 7.0 4499386 (Security Update) Important Security Feature Bypass Maybe

Patches

3 patches
Article Type Restart
4494412 Security Update Maybe
4498363 Security Update Maybe
4499386 Security Update Maybe

Known Exploits

Acknowledgments