SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-1018

An information disclosure vulnerability exists when Microsoft Dynamics Business Central/NAV on-premise does not properly hide the value of a masked field when showing the records as a chart page.The attacker who successfully exploited the vulnerability…

HIGH 7.5EPSS 6.31%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (6.31%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

An information disclosure vulnerability exists when Microsoft Dynamics Business Central/NAV on-premise does not properly hide the value of a masked field when showing the records as a chart page.The attacker who successfully exploited the vulnerability could see the information that are in a masked field.The security update addresses the vulnerability by updating the rendering engine the Windows client to properly detect masked fields and render the content as masked., aka 'Microsoft Dynamics Business Central/NAV Information Disclosure'.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
6.31% probability · 93th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
microsoft/dynamics 365 business central · microsoft/dynamics nav
Source
secure@microsoft.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.