🟠 High  |  Source: Microsoft Security Response Center


CVE-2024-21380 is an information disclosure vulnerability affecting Microsoft Dynamics Business Central and NAV, which could allow attackers to access sensitive data they should not be able to see. Microsoft has issued an update to build numbers associated with the advisory, though this latest change is administrative rather than a new patch. Organisations running affected versions should verify they are on patched builds to ensure they are protected.

Security Architect’s Take: Confirm that your Dynamics Business Central or NAV deployments are running the corrected build numbers listed in the updated advisory — cross-reference your current version against the MSRC update guide and prioritise patching any instances that remain on vulnerable builds.

Original advisory: CVE-2024-21380 Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability