CVE-2025-62211

8.7

Microsoft · Dynamics 365 Field Service

A cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 Field Service allows an authenticated attacker to perform spoofing attacks over a network.

Executive summary

A high-severity cross-site scripting vulnerability in Microsoft Dynamics 365 Field Service allows authenticated attackers to perform network-based spoofing attacks.

Vulnerability

This vulnerability involves improper neutralization of input during web page generation, classified as CWE-79. The flaw requires an authorized (authenticated) user to interact with the application, where they can inject malicious scripts to facilitate spoofing.

Business impact

The exploitation of this vulnerability could lead to unauthorized content injection and spoofing, which may be used to deceive users or harvest sensitive session information. With a CVSS score of 8.7, the risk is classified as High, reflecting the potential for significant impact on data integrity and user trust within the Dynamics 365 environment.

Remediation

Immediate Action: Organizations must update Microsoft Dynamics 365 Field Service to version 8.8.139.398 or later to remediate the underlying XSS flaw.

Proactive Monitoring: Security teams should monitor application access logs for unusual patterns or unexpected script execution attempts originating from authenticated user sessions.

Compensating Controls: Deploy or tune a Web Application Firewall (WAF) to detect and block suspicious cross-site scripting payloads directed at the Dynamics 365 interface.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit available.

Analyst recommendation

Given the High severity score and the potential for authenticated users to compromise the integrity of the web interface, this update should be prioritized in the next maintenance cycle. Administrators should verify that all instances are updated to version 8.8.139.398 immediately to eliminate the possibility of XSS-based spoofing.

More Microsoft CVEs

Sources