🟠 High  |  Source: Microsoft Security Response Center


CVE-2022-41127 is a remote code execution vulnerability affecting Microsoft Dynamics NAV and Dynamics 365 Business Central running in on-premises deployments. A successful exploit could allow an attacker to execute arbitrary code on affected systems, potentially leading to full system compromise. This update revises the affected build numbers but introduces no new security fixes.

Security Architect’s Take: Verify that all on-premises Dynamics NAV and Dynamics 365 Business Central instances are patched to the updated build numbers listed in the revised advisory. If you manage hybrid environments where on-premises Dynamics deployments interact with Azure services, treat unpatched nodes as a potential lateral movement risk and prioritise remediation accordingly.

Original advisory: CVE-2022-41127 Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability