CVE-2025-21177 is a Server-Side Request Forgery (SSRF) vulnerability in Microsoft Dynamics 365 Sales, allowing an authenticated attacker to achieve privilege escalation over a network. With a CVSS score of 8.8 (HIGH), this flaw presents a significant risk, enabling high impact to confidentiality, integrity, and availability with low attack complexity. While there is no evidence of active exploitation, public exploit code, or inclusion in CISA's KEV catalog, the vulnerability has garnered notable community discussion and media coverage, indicating awareness within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:dynamics_365_sales:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.