CVE-2019-1229 is an elevation of privilege vulnerability affecting Microsoft Dynamics On-Premise v9. An attacker with customizer privileges could exploit this by persisting malicious XAML script, gaining control of the Dynamics Web Role. This vulnerability has a high CVSS score of 8.8, indicating a significant risk with low attack complexity and potential for complete compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation is reported, the vulnerability has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.0CPE matchmatch criteria | cpe:2.3:a:microsoft:dynamics_365:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.