<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Dynamics-365 on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/dynamics-365/</link><description>Recent content in Dynamics-365 on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Wed, 18 Jun 2025 14:00:00 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/dynamics-365/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-47646: Dynamics 365 Customer Voice XSS Flaw</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-47646-dynamics-365-customer-voice-xss-spoofing/</link><pubDate>Thu, 18 Jun 2026 14:00:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-47646-dynamics-365-customer-voice-xss-spoofing/</guid><description>CVE-2026-47646 is an XSS spoofing vulnerability in Microsoft Dynamics 365 Customer Voice exploitable by unauthenticated attackers over a network.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47646">Microsoft Security Response Center</a></p>
<hr>
<p>CVE-2026-47646 is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 Customer Voice that allows an unauthenticated attacker to perform spoofing attacks over a network. The flaw stems from improper handling of user-supplied input during web page generation, meaning malicious content could be injected and rendered in a victim&rsquo;s browser. Because no authentication is required to exploit this, the potential reach is broad for any organisation using Customer Voice externally.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Review your Dynamics 365 Customer Voice deployments and ensure Microsoft&rsquo;s patch is applied promptly; additionally, assess whether any customer-facing survey links or embedded forms could be weaponised to deliver spoofed content to end users, and consider adding Content Security Policy (CSP) headers as a compensating control where supported.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47646">CVE-2026-47646 Dynamics 365 Customer Voice Spoofing Vulnerability</a></p>
]]></content:encoded></item><item><title>CVE-2026-47647: Dynamics 365 Privilege Escalation</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-47647-dynamics-365-elevation-of-privilege/</link><pubDate>Thu, 18 Jun 2026 14:00:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-47647-dynamics-365-elevation-of-privilege/</guid><description>CVE-2026-47647 is a Dynamics 365 elevation of privilege flaw allowing authenticated attackers to escalate permissions over a network. Patch now.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47647">Microsoft Security Response Center</a></p>
<hr>
<p>A flaw in Microsoft Dynamics 365 allows an already-authenticated attacker to gain higher privileges than they should have, purely over the network — no physical access required. This means a low-privileged user or compromised account could be leveraged to access sensitive business data or administrative functions within Dynamics 365. Given how widely Dynamics 365 is used for CRM and ERP workflows, the potential business impact is significant.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Audit current Dynamics 365 role assignments and apply the least-privilege principle immediately — remove any unnecessary elevated roles whilst Microsoft&rsquo;s patch is applied. Prioritise patching for tenants where Dynamics 365 is integrated with other Azure services or holds sensitive customer and financial data.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47647">CVE-2026-47647 Dynamics 365 Elevation of Privilege Vulnerability</a></p>
]]></content:encoded></item><item><title>CVE-2026-40371: Dynamics 365 On-Prem EoP Fix</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-40371-microsoft-dynamics-365-on-premises-elevation-of-privilege/</link><pubDate>Tue, 16 Jun 2026 14:00:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-40371-microsoft-dynamics-365-on-premises-elevation-of-privilege/</guid><description>Microsoft corrects patch guidance for CVE-2026-40371, a Dynamics 365 on-premises privilege escalation flaw. The real fix is in v9.1 Update 1.45.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40371">Microsoft Security Response Center</a></p>
<hr>
<p>A privilege escalation vulnerability in Microsoft Dynamics 365 on-premises has been assigned CVE-2026-40371, allowing an attacker to gain elevated permissions within the application. Microsoft has corrected its remediation guidance: the fix is contained in Dynamics 365 Server v9.1 Update 1.45 (build 9.1.0045.0011), not the previously stated version 6.2. Organisations that applied the earlier guidance should verify they are running the correct build to ensure they are actually protected.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Audit your Dynamics 365 on-premises deployments immediately and confirm the installed build is 9.1.0045.0011 or later — do not assume earlier patching attempts were sufficient given the corrected version guidance. If you manage hybrid environments where on-premises Dynamics 365 integrates with Azure services, treat unpatched instances as a potential lateral movement risk and prioritise the update accordingly.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40371">CVE-2026-40371 Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability</a></p>
]]></content:encoded></item></channel></rss>