🟠 High  |  Source: Microsoft Security Response Center


CVE-2024-38225 is an elevation of privilege vulnerability affecting Microsoft Dynamics 365 Business Central, a cloud-based ERP platform hosted on Azure. Successful exploitation could allow an attacker to gain higher-level permissions than intended within the application. This update revises the affected build numbers and is informational in nature, with no new patches issued.

Security Architect’s Take: Verify that your Dynamics 365 Business Central environment is running a build number confirmed as patched in the updated advisory, and ensure auto-update policies are active for your tenant. Review privileged role assignments within Business Central to reduce the blast radius should exploitation occur.

Original advisory: CVE-2024-38225 Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability