CVE-2025-62210
8.7Microsoft · Dynamics 365 Field Service (online)
A cross-site scripting vulnerability in Microsoft Dynamics 365 Field Service allows an authenticated attacker to perform content spoofing via the network.
Executive summary
A high-severity cross-site scripting vulnerability in Microsoft Dynamics 365 Field Service (online) allows authenticated attackers to perform malicious spoofing, posing a significant risk to data integrity.
Vulnerability
This flaw involves improper neutralization of input during web page generation, classified as CWE-79. The vulnerability requires the attacker to have authorized access to the application to trigger the cross-site scripting mechanism.
Business impact
The vulnerability carries a CVSS score of 8.7, indicating a high level of risk for organizational workflows. Successful exploitation allows an attacker to inject malicious scripts into the application environment, facilitating spoofing attacks that can deceive users, compromise session integrity, and undermine the trustworthiness of business communications within the platform.
Remediation
Immediate Action: Update the Microsoft Dynamics 365 Field Service (online) instance to version 8.8.139.398 or higher as specified by the vendor security update.
Proactive Monitoring: Review application access logs for unusual patterns, particularly inputs containing script tags or unexpected redirects that deviate from standard user activity.
Compensating Controls: Ensure that a robust Content Security Policy (CSP) is implemented and that Web Application Firewalls are configured to inspect and block common cross-site scripting payloads.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS score and the potential for session or content manipulation, organizations should prioritize updating their Dynamics 365 environments immediately. Administrators must ensure that all instances are patched beyond the vulnerable version range to neutralize the risk of unauthorized script execution and spoofing.
More Microsoft CVEs
Sources
- Dynamics 365 Field Service (online) Spoofing Vulnerability Vendor advisory