Microsoft Dynamics
CVE-2020-1022 — Dynamics Business Central Remote Code Execution Vulnerability
Executive Summary
A remote code execution vulnerability exists in Microsoft Dynamics Business Central. An attacker who successfully exploited this vulnerability could execute arbitrary shell commands on victim's server. To exploit the vulnerability, an authenticated attacker needs to convince the victim into connect to a malicious Dynamics Business Central client or elevate permission to system to perform the code execution. The security update addresses the vulnerability by preventing the possibility of using a binary type that could eventually execute code on the victim’s server.
Overview
8
CVSS HIGH
Critical
MS Severity
Not Exploited
MS Exploit Status
Less Likely
MS Exploit Likelihood
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
ATTACK VECTOR
Network
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
Low
USER INTERACTION
Required
SCOPE
Unchanged
EPSS Score
0.06831
probability of exploitation in the next 30 days
0.93194 percentile - updated 2026-06-21
View on FIRST.org
Affected Products
8 affected products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Dynamics 365 Business Central 2019 Release Wave 2 (On-Premise) | 4549678 (Security Update) |
Critical | Remote Code Execution | Maybe |
| Dynamics 365 Business Central 2019 Spring Update | 4549677 (Security Update) |
Critical | Remote Code Execution | Maybe |
| Microsoft Dynamics 365 BC On Premise | 4549676 (Security Update) |
Critical | Remote Code Execution | Maybe |
| Microsoft Dynamics NAV 2013 | 4557699 (Security Update) |
Critical | Remote Code Execution | Maybe |
| Microsoft Dynamics NAV 2015 | 4557700 (Security Update) |
Critical | Remote Code Execution | Maybe |
| Microsoft Dynamics NAV 2016 | 4549673 (Security Update) |
Critical | Remote Code Execution | Maybe |
| Microsoft Dynamics NAV 2017 | 4549674 (Security Update) |
Critical | Remote Code Execution | Maybe |
| Microsoft Dynamics NAV 2018 | 4549675 (Security Update) |
Critical | Remote Code Execution | Maybe |
Patches
8 patches
| Article | Type | Restart |
|---|---|---|
4549678 |
Security Update | Maybe |
4549677 |
Security Update | Maybe |
4549676 |
Security Update | Maybe |
4557699 |
Security Update | Maybe |
4557700 |
Security Update | Maybe |
4549673 |
Security Update | Maybe |
4549674 |
Security Update | Maybe |
4549675 |
Security Update | Maybe |
Known Exploits
No known exploits have been linked for this CVE yet. When available, exploit references will be sourced from public repositories and may be unverified, incomplete, or non-functional. Always review code carefully before use in any environment.
Acknowledgments
References
On This Page