« Volver al listado

CVE-2022-41066

Estado: ModificadaMedia (4.4)—

Microsoft Dynamics Business Central Information Disclosure Vulnerability

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-41066",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "secure@microsoft.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 0.7
      },
      {
        "type": "Secondary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 0.7
      }
    ]
  },
  "affected": [
    {
      "source": "secure@microsoft.com",
      "affectedData": [
        {
          "vendor": "Microsoft",
          "product": "Dynamics 365 Business Central Spring 2019 Update",
          "versions": [
            {
              "status": "affected",
              "version": "14.0.0",
              "lessThan": "14.0.49339",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Microsoft Dynamics 365 Business Central 2021 Release Wave 2",
          "versions": [
            {
              "status": "affected",
              "version": "19.0.0",
              "lessThan": "19.0.48446",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Microsoft Dynamics 365 Business Central 2022 Release Wave 1",
          "versions": [
            {
              "status": "affected",
              "version": "20.0.0",
              "lessThan": "20.0.48457",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Microsoft Dynamics 365 Business Central 2022 Release Wave 2",
          "versions": [
            {
              "status": "affected",
              "version": "21.0.0",
              "lessThan": "21.0.48504",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Microsoft Dynamics NAV 2018",
          "versions": [
            {
              "status": "affected",
              "version": "1.0",
              "lessThan": "49345",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-11-09T22:15:21.070",
  "references": [
    {
      "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41066",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secure@microsoft.com"
    },
    {
      "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41066",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Microsoft Dynamics Business Central Information Disclosure Vulnerability"
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de divulgación de información de Microsoft Business Central"
    }
  ],
  "lastModified": "2026-08-10T16:18:19.200",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:microsoft:dynamics_365_business_central_2019:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7B4AC243-AFB8-4735-B3BA-42677448216D",
              "versionEndExcluding": "14.42.49347"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:dynamics_365_business_central_2021:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1E97209C-6B3C-4E82-A788-239BBF042316",
              "versionEndIncluding": "19.18.54872"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:dynamics_365_business_central_2022:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3527F043-462D-4EE9-88EA-F3805B5A882B",
              "versionEndExcluding": "20.7.48483"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:dynamics_365_business_central_2022:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D0F801EA-68D1-42AD-B956-BF3951E7ED1E",
              "versionEndExcluding": "21.1.48638",
              "versionStartIncluding": "21.1.48638"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:dynamics_nav:2018:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FA8EA7FF-BEE3-47A5-B711-83191CBFCE40"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secure@microsoft.com"
}