Critical CVSS 7.1 EPSS 0.02466 2020-09 archive

Executive Summary

A remote code execution vulnerability exists in Microsoft Dynamics 365 for Finance and Operations (on-premises) version 10.0.11. An attacker who successfully exploited this vulnerability could gain remote code execution via server-side script execution on the victim server. An authenticated attacker with privileges to import and export data could exploit this vulnerability by sending a specially crafted file to a vulnerable Dynamics server. The security update addresses the vulnerability by correcting how Microsoft Dynamics 365 for Finance and Operations (on-premises) version 10.0.11 handles user input.

Overview

7.1
CVSS HIGH
Critical
MS Severity
Not Exploited
MS Exploit Status
Not Found
MS Exploit Likelihood
Category Remote Code Execution
Released Sep 8 2020
Last Updated Sep 8 2020
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.02466 — 0.82387 percentile
NVD CVSS 7.1 HIGH — matches MSRC

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:N/E:P/RL:O/RC:C
ATTACK VECTOR
Network
ATTACK COMPLEXITY
High
PRIVILEGES REQUIRED
Low
USER INTERACTION
None
SCOPE
Changed
CONFIDENTIALITY
Low
INTEGRITY
High
AVAILABILITY
None
EXPLOIT CODE MATURITY
Proof-of-Concept
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 6.4

EPSS Score

0.02466
probability of exploitation in the next 30 days
0.82387 percentile - updated 2026-06-21
View on FIRST.org

Affected Products

1 affected product
Product KB Article Severity Impact Restart Required
Dynamics 365 for Finance and Operations Release Notes (Security Update) Critical Remote Code Execution Maybe

Patches

1 patch
Article Type Restart
Release Notes Security Update Maybe

Known Exploits

Acknowledgments