Microsoft Send Customer Voice survey from Dynamics 365 Spoofing Vulnerability
CVE-2023-36007
7.6HIGH
Key Information:
- Vendor
- Microsoft
- Vendor
- CVE Published:
- 14 November 2023
Summary
The vulnerability allows an attacker to spoof legitimate customer feedback surveys sent through the Microsoft Dynamics 365 platform, potentially misleading users and compromising data integrity. Exploiting this vulnerability could result in unauthorized access to user interactions and surveys, posing a risk to both organizations and their customers. It is essential for users of Dynamics 365 to stay informed about this issue and implement the recommended security measures to mitigate potential exploits.
Affected Version(s)
Send Customer Voice survey from Dynamics 365 app Unknown 1.0.0.0 < 9.0.0.8
References
CVSS V3.1
Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved