CVE-2023-36007 is a spoofing vulnerability affecting Microsoft Send Customer Voice survey from Dynamics 365. With a CVSS score of 4.1 (Medium), it requires user interaction and low privileges, allowing an attacker to spoof content with low impact on integrity. There is currently no known active exploitation, public exploit code, or Metasploit/Nuclei modules available. While community discussion and media coverage are minimal, Microsoft addressed this flaw in its November 2023 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.0.0.8CPE matchmatch criteria | cpe:2.3:a:microsoft:send_customer_voice_survey_from_dynamics_365:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.