CVE-2022-41066 is an information disclosure vulnerability affecting Microsoft Dynamics 365 Business Central and Dynamics NAV. With a CVSS score of 4.4 (Medium), it requires high privileges and high attack complexity, but successful exploitation could lead to sensitive data exposure. While not currently listed in CISA's KEV catalog, its EPSS score indicates a higher than average probability of exploitation. There is no public exploit code available, and community discussion and media coverage are minimal, suggesting limited current attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 14.42.49347CPE matchmatch criteria | cpe:2.3:a:microsoft:dynamics_365_business_central_2019:*:*:*:*:*:*:*:* | ||
<= 19.18.54872CPE matchmatch criteria | cpe:2.3:a:microsoft:dynamics_365_business_central_2021:*:*:*:*:*:*:*:* | ||
< 20.7.48483CPE matchmatch criteria | cpe:2.3:a:microsoft:dynamics_365_business_central_2022:*:*:*:*:*:*:*:* | ||
>= 21.1.48638, < 21.1.48638CPE matchmatch criteria | cpe:2.3:a:microsoft:dynamics_365_business_central_2022:*:*:*:*:*:*:*:* | ||
2018CPE matchmatch criteria | cpe:2.3:a:microsoft:dynamics_nav:2018:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.