CVE-2014-0261
Microsoft Dynamics AX 4.0 SP2, 2009 SP1, 2012, and 2012 R2 allows remote authenticated users to cause a denial of service (instance outage) via crafted data to an Application Object Server (AOS) instance, aka "Query Filter DoS Vulnerability."
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.3%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.
Description
Microsoft Dynamics AX 4.0 SP2, 2009 SP1, 2012, and 2012 R2 allows remote authenticated users to cause a denial of service (instance outage) via crafted data to an Application Object Server (AOS) instance, aka "Query Filter DoS Vulnerability."
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
- EPSS
- 10.30% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- microsoft/dynamics ax
- Source
- secure@microsoft.com
References
- http://www.securitytracker.com/id/1029601Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-004
- http://www.securitytracker.com/id/1029601Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-004
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.