🔴 Critical  |  Source: Microsoft Security Response Center


CVE-2021-34474 is a remote code execution vulnerability in Microsoft Dynamics 365 Business Central, a cloud-based ERP platform. This update revises the affected build numbers but introduces no new patches or mitigations. Organisations running unpatched versions of Business Central remain at risk of an attacker executing arbitrary code on affected systems.

Security Architect’s Take: Verify that your Dynamics 365 Business Central deployments are running the corrected build numbers listed in the updated advisory, and ensure the original July 2021 patches have been applied. If Business Central is internet-facing or integrated with other Azure services, prioritise confirmation of patch status given the remote code execution impact.

Original advisory: CVE-2021-34474 Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability