CVE-2024-38225

Summary

Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability

Affected Software

VendorProductVersion RangeStatus
MicrosoftMicrosoft Dynamics 365 Business Central 2023 Release Wave 122.0.0 < 22.0.64727affected
MicrosoftMicrosoft Dynamics 365 Business Central 2023 Release Wave 223.0.0 < 24.0.22865affected
MicrosoftMicrosoft Dynamics 365 Business Central 2024 Release Wave 124.0 < 23.0.22561affected

Weaknesses

  • CWE-287: CWE-287: Improper Authentication

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References