🟡 Medium | Source: Microsoft Security Response Center
CVE-2025-29821 is an information disclosure vulnerability affecting Microsoft Dynamics 365 Business Central, a cloud-based ERP platform. The latest update from Microsoft revises the affected build numbers but carries no changes to the underlying vulnerability details or severity rating. Organisations running Business Central should verify whether their deployed build falls within the affected range.
Security Architect’s Take: Review the updated build numbers published by Microsoft and confirm your Business Central environment is running a patched version. If you manage Business Central Online, Microsoft typically applies patches automatically, but on-premises or private cloud deployments require manual verification and patching.
Original advisory: CVE-2025-29821 Microsoft Dynamics Business Central Information Disclosure Vulnerability