Critical CVSS 8.7 EPSS 0.01012 2025-02 archive

Executive Summary

Server-Side Request Forgery (SSRF) in Microsoft Dynamics 365 Sales allows an authorized attacker to elevate privileges over a network.

Overview

8.7
CVSS HIGH
Critical
MS Severity
Not Exploited
MS Exploit Status
N/A
MS Exploit Likelihood
Category Elevation of Privilege
Released Feb 11 2025
Last Updated Feb 11 2025
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.01012 — 0.5864 percentile

CVSS Vector

ATTACK VECTOR
Network
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
Low
USER INTERACTION
Required
SCOPE
Changed
Temporal Score: 7.6

EPSS Score

0.01012
probability of exploitation in the next 30 days
0.5864 percentile - updated 2026-06-20
View on FIRST.org

Affected Products

1 affected product
Product KB Article Severity Impact Restart Required
Dynamics 365 Sales Critical Elevation of Privilege Unknown

Patches

1 patch
Article Type Restart
Unknown

Known Exploits

Acknowledgments