CVE-2026-65772

8.8

Microsoft · Microsoft Dynamics 365 (on-premises)

An insecure deserialization vulnerability in Microsoft Dynamics 365 (on-premises) allows an authenticated attacker to execute arbitrary code over the network.

Executive summary

An insecure deserialization flaw in Microsoft Dynamics 365 (on-premises) poses a high risk of remote code execution for authenticated attackers.

Vulnerability

The vulnerability stems from the insecure deserialization of untrusted data (CWE-502). An attacker with low-level authenticated access can leverage this flaw to execute code on the host system over a network connection.

Business impact

The ability to execute arbitrary code on a core business platform like Dynamics 365 presents a severe threat to data integrity, confidentiality, and system availability. Given the CVSS score of 8.8, this vulnerability is categorized as high severity because it enables lateral movement and full system compromise within the server environment. Successful exploitation could result in the total loss of control over the affected application and the sensitive business data stored within it.

Remediation

Immediate Action: Update Microsoft Dynamics 365 (on-premises) to version 9.1.0046.0006 or later to address the deserialization vulnerability.

Proactive Monitoring: Monitor server logs for unexpected process execution or abnormal spikes in CPU usage that might indicate unauthorized code execution attempts.

Compensating Controls: Ensure that the application is not exposed directly to the internet and utilize network segmentation to restrict access to the Dynamics 365 management interface.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability represents a critical risk to the security of your on-premises infrastructure. Organizations should prioritize the deployment of the vendor-provided update identified in the remediation section. Testing the patch in a staging environment prior to deployment is advised, but the high severity of the flaw necessitates a rapid transition to production environments.

More Microsoft CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources