Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-41127

28
FAUCET Score

CVE-2022-41127 is a remote code execution vulnerability affecting Microsoft Dynamics NAV and Dynamics 365 Business Central (On-Premises). With a CVSS score of 8.5 (High), successful exploitation requires low privileges but high attack complexity, potentially leading to complete compromise of confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog and lacking public exploit code in Metasploit or ExploitDB, it has garnered limited community discussion and media coverage, including a mention in Microsoft's December 2022 Patch Tuesday.

Impacted Technologies

VendorProductVersion(s)CPE
2019CPE matchmatch criteria
cpe:2.3:a:microsoft:dynamics_365_business_central:2019:release_wave_2:*:*:on-premise:*:*:*
2019CPE matchmatch criteria
cpe:2.3:a:microsoft:dynamics_365_business_central:2019:spring_update:*:*:*:*:*:*
2020CPE matchmatch criteria
cpe:2.3:a:microsoft:dynamics_365_business_central:2020:release_wave_1:*:*:*:*:*:*
2020CPE matchmatch criteria
cpe:2.3:a:microsoft:dynamics_365_business_central:2020:release_wave_2:*:*:*:*:*:*
2021CPE matchmatch criteria
cpe:2.3:a:microsoft:dynamics_365_business_central:2021:release_wave_1:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.5HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.57%
Probability of exploitation in next 30 days
EPSS Percentile
72.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0157 is in the 69th percentile among its peer group of 1,162 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (13)

microsoftpatch availablevia msrc
Product: Microsoft Dynamics NAV 2016Fixed in: Build 52203
View patch
microsoftpatch availablevia msrc
Product: Microsoft Dynamics NAV 2017Fixed in: Build 30712
View patch
microsoftpatch availablevia msrc
Product: Microsoft Dynamics NAV 2018Fixed in: Build 49497
View patch
microsoftpatch availablevia msrc
Product: Microsoft Dynamics NAV 2015Fixed in: 52204
microsoftpatch availablevia msrc
Product: Dynamics 365 Business Central Spring 2019 UpdateFixed in: App Build 14.43.49498, Platform Build 14.0.49494
View patch
microsoftpatch availablevia msrc
Product: Dynamics 365 Business Central 2019 Release Wave 2 (On-Premise)Fixed in: App Build 15.17.48428, Platform Build 15.0.48
View patch
microsoftpatch availablevia msrc
Product: Microsoft Dynamics 365 Business Central 2020 Release Wave 2Fixed in: App Build 17.17.38111, Platform Build 17.0.38061
View patch
microsoftpatch availablevia msrc
Product: Microsoft Dynamics 365 Business Central 2020 Release Wave 1Fixed in: App Build 16.19.35126, Platform Build 16.35120
View patch
microsoftpatch availablevia msrc
Product: Microsoft Dynamics 365 Business Central 2022 Release Wave 1Fixed in: App Build 20.8.49971, Platform Build 20.0.49947
View patch
microsoftpatch availablevia msrc
Product: Microsoft Dynamics 365 Business Central 2021 Release Wave 2Fixed in: App Build 19.14.49970, Platform Build 19.0.49925
View patch
microsoftpatch availablevia msrc
Product: Microsoft Dynamics 365 Business Central 2022 Release Wave 2Fixed in: App Build 21.2.49990, Platform Build 21.0.49984
View patch
microsoftpatch availablevia msrc
Product: Microsoft Dynamics 365 Business Central 2021 Release Wave 1Fixed in: App Build 18.18.46920, Platform Build 18.0.46905
View patch
microsoftpatch availablevia msrc
Product: Microsoft Dynamics NAV 2013 R2Fixed in: 52297
View patch

Vendor Advisories (1)

microsoft2022-Dec/CVE-2022-41127Critical

Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability

Dec 13, 2022

References

msrc.microsoft.com / update-guide/vulnerability/CVE-2022-41127