« Volver al listado

CVE-2025-29821

Estado: AnalizadaMedia (5.5)—

Improper input validation in Dynamics Business Central allows an authorized attacker to disclose information locally.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-29821",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-29821",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-08T20:05:23.735248Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "secure@microsoft.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "secure@microsoft.com",
      "affectedData": [
        {
          "vendor": "Microsoft",
          "product": "Microsoft Dynamics 365 Business Central 2023 Wave 2",
          "versions": [
            {
              "status": "affected",
              "version": "23.0",
              "lessThan": "23.0.32309",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Microsoft Dynamics 365 Business Central 2024 Wave 1 2024",
          "versions": [
            {
              "status": "affected",
              "version": "24.0",
              "lessThan": "24.0.32305",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Microsoft Dynamics 365 Business Central 2024 Wave 2",
          "versions": [
            {
              "status": "affected",
              "version": "25.0",
              "lessThan": "25.2.32308",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Microsoft Dynamics 365 Business Central 2025 Wave 1",
          "versions": [
            {
              "status": "affected",
              "version": "26.0",
              "lessThan": "26.0.32481",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-04-08T18:16:07.867",
  "references": [
    {
      "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29821",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secure@microsoft.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secure@microsoft.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper input validation in Dynamics Business Central allows an authorized attacker to disclose information locally."
    },
    {
      "lang": "es",
      "value": "La validación de entrada incorrecta en Dynamics Business Central permite que un atacante autorizado divulgue información localmente."
    }
  ],
  "lastModified": "2026-08-10T16:19:27.087",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:microsoft:dynamics_365_business_central_2023:*:*:*:*:on-premise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0285AA8A-CCA9-4BBD-9655-338B2E7AD648",
              "versionEndExcluding": "23.18.32409",
              "versionStartIncluding": "23.1.13812"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:dynamics_365_business_central_2024:*:*:*:*:on-premise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0404B3E7-5E7F-4926-B390-8D8FD7E5C788",
              "versionEndExcluding": "24.12.32447"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:dynamics_365_business_central_2024:*:*:*:*:on-premise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B95E007F-0534-4A0B-8A7F-D85C4F199245",
              "versionEndExcluding": "25.6.32556",
              "versionStartIncluding": "25.1.25900"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:dynamics_365_business_central_2025:*:*:*:*:on-premise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "72BE4EFA-54D8-4161-92CA-D0A613439DE4",
              "versionEndExcluding": "26.0.32481"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secure@microsoft.com"
}