🟠 High  |  Source: Microsoft Security Response Center


CVE-2024-35248 is an elevation of privilege vulnerability in Microsoft Dynamics 365 Business Central, a cloud-based ERP platform. If exploited, it could allow an attacker to gain higher-level permissions than intended within the application. Microsoft has issued an informational update revising the affected build numbers, with no change to the underlying guidance.

Security Architect’s Take: Verify that your Dynamics 365 Business Central environments are running patched build versions as listed in the updated advisory, and confirm your software update policies are pulling the latest release. No additional remediation steps are indicated beyond applying the previously released fix.

Original advisory: CVE-2024-35248 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability