Weak authentication in Microsoft Dynamics 365 allows an unauthenticated attacker to elevate privileges over a network.
The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.
Link | Tags |
---|---|
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38182 | vendor advisory |