Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability

Vulnerability

A vulnerability in Microsoft Dynamics 365 (on-premises) version 9.1 allows unauthorized actors to disclose sensitive information over the network. This issue arises from improper handling of information, which could be exploited by clicking on a specially crafted URL that directs to a malicious site, where the attacker could execute queries to extract sensitive data.

Impact

Exploitation of this vulnerability could lead to unauthorized disclosure of sensitive information.

Remediation

Users can apply the official security update available through the Microsoft Update Catalog to address this vulnerability.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.4
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.