CVE-2025-62210

8.7

Microsoft · Dynamics 365 Field Service (online)

A cross-site scripting vulnerability in Microsoft Dynamics 365 Field Service allows an authenticated attacker to perform content spoofing via the network.

Executive summary

A high-severity cross-site scripting vulnerability in Microsoft Dynamics 365 Field Service (online) allows authenticated attackers to perform malicious spoofing, posing a significant risk to data integrity.

Vulnerability

This flaw involves improper neutralization of input during web page generation, classified as CWE-79. The vulnerability requires the attacker to have authorized access to the application to trigger the cross-site scripting mechanism.

Business impact

The vulnerability carries a CVSS score of 8.7, indicating a high level of risk for organizational workflows. Successful exploitation allows an attacker to inject malicious scripts into the application environment, facilitating spoofing attacks that can deceive users, compromise session integrity, and undermine the trustworthiness of business communications within the platform.

Remediation

Immediate Action: Update the Microsoft Dynamics 365 Field Service (online) instance to version 8.8.139.398 or higher as specified by the vendor security update.

Proactive Monitoring: Review application access logs for unusual patterns, particularly inputs containing script tags or unexpected redirects that deviate from standard user activity.

Compensating Controls: Ensure that a robust Content Security Policy (CSP) is implemented and that Web Application Firewalls are configured to inspect and block common cross-site scripting payloads.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS score and the potential for session or content manipulation, organizations should prioritize updating their Dynamics 365 environments immediately. Administrators must ensure that all instances are patched beyond the vulnerable version range to neutralize the risk of unauthorized script execution and spoofing.

More Microsoft CVEs

Sources