{
  "document": {
    "acknowledgments": [
      {
        "names": [
          "Yiming Xiang with <a href=\"https://www.nsfocus.cn/\">NSFOCUS TIANJI LAB</a>"
        ]
      }
    ],
    "aggregate_severity": {
      "namespace": "https://www.microsoft.com/en-us/msrc/security-update-severity-rating-system",
      "text": "Critical"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Public",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en-US",
    "notes": [
      {
        "category": "general",
        "text": "To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle",
        "title": "Additional Resources"
      },
      {
        "category": "legal_disclaimer",
        "text": "The information provided in the Microsoft Knowledge Base is provided \\\"as is\\\" without warranty of any kind. Microsoft disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply.",
        "title": "Disclaimer"
      },
      {
        "category": "general",
        "text": "Required. The vulnerability documented by this CVE requires customer action to resolve.",
        "title": "Customer Action"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "secure@microsoft.com",
      "name": "Microsoft Security Response Center",
      "namespace": "https://msrc.microsoft.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "CVE-2022-41127 Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability - HTML",
        "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41127"
      },
      {
        "category": "self",
        "summary": "CVE-2022-41127 Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability - CSAF",
        "url": "https://msrc.microsoft.com/csaf/advisories/2022/msrc_cve-2022-41127.json"
      },
      {
        "category": "external",
        "summary": "Microsoft Exploitability Index",
        "url": "https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1"
      },
      {
        "category": "external",
        "summary": "Microsoft Support Lifecycle",
        "url": "https://support.microsoft.com/lifecycle"
      },
      {
        "category": "external",
        "summary": "Common Vulnerability Scoring System",
        "url": "https://www.first.org/cvss"
      }
    ],
    "title": "Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability",
    "tracking": {
      "current_release_date": "2023-10-10T07:00:00.000Z",
      "generator": {
        "date": "2025-07-22T17:49:26.508Z",
        "engine": {
          "name": "MSRC Generator",
          "version": "1.0"
        }
      },
      "id": "msrc_CVE-2022-41127",
      "initial_release_date": "2022-12-13T08:00:00.000Z",
      "revision_history": [
        {
          "date": "2022-12-13T08:00:00.000Z",
          "legacy_version": "1",
          "number": "1",
          "summary": "Information published."
        },
        {
          "date": "2022-12-20T08:00:00.000Z",
          "legacy_version": "1.1",
          "number": "2",
          "summary": "Corrected Download and Article links in the Security Updates table. This is an informational change only."
        },
        {
          "date": "2023-03-14T07:00:00.000Z",
          "legacy_version": "2",
          "number": "3",
          "summary": "In the Security Updates table, added the following supported editions of Microsoft Dynamics NAV as they are affected by this vulnerability: Microsoft Dynamics NAV 2013 R2 and Microsoft Dynamics NAV 2015. Microsoft strongly recommends that customers install the updates to be fully protected from this vulnerability."
        },
        {
          "date": "2023-10-10T07:00:00.000Z",
          "legacy_version": "2.1",
          "number": "4",
          "summary": "Corrected security updates table.  This is an informational change only."
        }
      ],
      "status": "final",
      "version": "4"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "category": "product_version_range",
            "name": "<Build 52203",
            "product": {
              "name": "Microsoft Dynamics NAV 2016 <Build 52203",
              "product_id": "13"
            }
          },
          {
            "category": "product_version",
            "name": "Build 52203",
            "product": {
              "name": "Microsoft Dynamics NAV 2016 Build 52203",
              "product_id": "11602"
            }
          }
        ],
        "category": "product_name",
        "name": "Microsoft Dynamics NAV 2016"
      },
      {
        "branches": [
          {
            "category": "product_version_range",
            "name": "<Build 30712",
            "product": {
              "name": "Microsoft Dynamics NAV 2017 <Build 30712",
              "product_id": "12"
            }
          },
          {
            "category": "product_version",
            "name": "Build 30712",
            "product": {
              "name": "Microsoft Dynamics NAV 2017 Build 30712",
              "product_id": "11603"
            }
          }
        ],
        "category": "product_name",
        "name": "Microsoft Dynamics NAV 2017"
      },
      {
        "branches": [
          {
            "category": "product_version_range",
            "name": "<Build 49497",
            "product": {
              "name": "Microsoft Dynamics NAV 2018 <Build 49497",
              "product_id": "10"
            }
          },
          {
            "category": "product_version",
            "name": "Build 49497",
            "product": {
              "name": "Microsoft Dynamics NAV 2018 Build 49497",
              "product_id": "11746"
            }
          }
        ],
        "category": "product_name",
        "name": "Microsoft Dynamics NAV 2018"
      },
      {
        "branches": [
          {
            "category": "product_version_range",
            "name": "<52204",
            "product": {
              "name": "Microsoft Dynamics NAV 2015 <52204",
              "product_id": "9"
            }
          },
          {
            "category": "product_version",
            "name": "52204",
            "product": {
              "name": "Microsoft Dynamics NAV 2015 52204",
              "product_id": "11747"
            }
          }
        ],
        "category": "product_name",
        "name": "Microsoft Dynamics NAV 2015"
      },
      {
        "branches": [
          {
            "category": "product_version_range",
            "name": "<App Build 14.43.49498, Platform Build 14.0.49494",
            "product": {
              "name": "Dynamics 365 Business Central Spring 2019 Update <App Build 14.43.49498, Platform Build 14.0.49494",
              "product_id": "8"
            }
          },
          {
            "category": "product_version",
            "name": "App Build 14.43.49498, Platform Build 14.0.49494",
            "product": {
              "name": "Dynamics 365 Business Central Spring 2019 Update App Build 14.43.49498, Platform Build 14.0.49494",
              "product_id": "11750"
            }
          }
        ],
        "category": "product_name",
        "name": "Dynamics 365 Business Central Spring 2019 Update"
      },
      {
        "branches": [
          {
            "category": "product_version_range",
            "name": "<App Build 15.17.48428, Platform Build 15.0.48",
            "product": {
              "name": "Dynamics 365 Business Central 2019 Release Wave 2 (On-Premise) <App Build 15.17.48428, Platform Build 15.0.48",
              "product_id": "7"
            }
          },
          {
            "category": "product_version",
            "name": "App Build 15.17.48428, Platform Build 15.0.48",
            "product": {
              "name": "Dynamics 365 Business Central 2019 Release Wave 2 (On-Premise) App Build 15.17.48428, Platform Build 15.0.48",
              "product_id": "11751"
            }
          }
        ],
        "category": "product_name",
        "name": "Dynamics 365 Business Central 2019 Release Wave 2 (On-Premise)"
      },
      {
        "branches": [
          {
            "category": "product_version_range",
            "name": "<App Build 17.17.38111, Platform Build 17.0.38061",
            "product": {
              "name": "Microsoft Dynamics 365 Business Central 2020 Release Wave 2 <App Build 17.17.38111, Platform Build 17.0.38061",
              "product_id": "6"
            }
          },
          {
            "category": "product_version",
            "name": "App Build 17.17.38111, Platform Build 17.0.38061",
            "product": {
              "name": "Microsoft Dynamics 365 Business Central 2020 Release Wave 2 App Build 17.17.38111, Platform Build 17.0.38061",
              "product_id": "11859"
            }
          }
        ],
        "category": "product_name",
        "name": "Microsoft Dynamics 365 Business Central 2020 Release Wave 2"
      },
      {
        "branches": [
          {
            "category": "product_version_range",
            "name": "<App Build 16.19.35126, Platform Build 16.35120",
            "product": {
              "name": "Microsoft Dynamics 365 Business Central 2020 Release Wave 1 <App Build 16.19.35126, Platform Build 16.35120",
              "product_id": "5"
            }
          },
          {
            "category": "product_version",
            "name": "App Build 16.19.35126, Platform Build 16.35120",
            "product": {
              "name": "Microsoft Dynamics 365 Business Central 2020 Release Wave 1 App Build 16.19.35126, Platform Build 16.35120",
              "product_id": "11860"
            }
          }
        ],
        "category": "product_name",
        "name": "Microsoft Dynamics 365 Business Central 2020 Release Wave 1"
      },
      {
        "branches": [
          {
            "category": "product_version_range",
            "name": "<App Build 20.8.49971, Platform Build 20.0.49947",
            "product": {
              "name": "Microsoft Dynamics 365 Business Central 2022 Release Wave 1 <App Build 20.8.49971, Platform Build 20.0.49947",
              "product_id": "3"
            }
          },
          {
            "category": "product_version",
            "name": "App Build 20.8.49971, Platform Build 20.0.49947",
            "product": {
              "name": "Microsoft Dynamics 365 Business Central 2022 Release Wave 1 App Build 20.8.49971, Platform Build 20.0.49947",
              "product_id": "12122"
            }
          }
        ],
        "category": "product_name",
        "name": "Microsoft Dynamics 365 Business Central 2022 Release Wave 1"
      },
      {
        "branches": [
          {
            "category": "product_version_range",
            "name": "<App Build 19.14.49970, Platform Build 19.0.49925",
            "product": {
              "name": "Microsoft Dynamics 365 Business Central 2021 Release Wave 2 <App Build 19.14.49970, Platform Build 19.0.49925",
              "product_id": "2"
            }
          },
          {
            "category": "product_version",
            "name": "App Build 19.14.49970, Platform Build 19.0.49925",
            "product": {
              "name": "Microsoft Dynamics 365 Business Central 2021 Release Wave 2 App Build 19.14.49970, Platform Build 19.0.49925",
              "product_id": "12123"
            }
          }
        ],
        "category": "product_name",
        "name": "Microsoft Dynamics 365 Business Central 2021 Release Wave 2"
      },
      {
        "branches": [
          {
            "category": "product_version_range",
            "name": "<App Build 21.2.49990, Platform Build 21.0.49984",
            "product": {
              "name": "Microsoft Dynamics 365 Business Central 2022 Release Wave 2 <App Build 21.2.49990, Platform Build 21.0.49984",
              "product_id": "4"
            }
          },
          {
            "category": "product_version",
            "name": "App Build 21.2.49990, Platform Build 21.0.49984",
            "product": {
              "name": "Microsoft Dynamics 365 Business Central 2022 Release Wave 2 App Build 21.2.49990, Platform Build 21.0.49984",
              "product_id": "12109"
            }
          }
        ],
        "category": "product_name",
        "name": "Microsoft Dynamics 365 Business Central 2022 Release Wave 2"
      },
      {
        "branches": [
          {
            "category": "product_version_range",
            "name": "<App Build 18.18.46920, Platform Build 18.0.46905",
            "product": {
              "name": "Microsoft Dynamics 365 Business Central 2021 Release Wave 1 <App Build 18.18.46920, Platform Build 18.0.46905",
              "product_id": "1"
            }
          },
          {
            "category": "product_version",
            "name": "App Build 18.18.46920, Platform Build 18.0.46905",
            "product": {
              "name": "Microsoft Dynamics 365 Business Central 2021 Release Wave 1 App Build 18.18.46920, Platform Build 18.0.46905",
              "product_id": "12132"
            }
          }
        ],
        "category": "product_name",
        "name": "Microsoft Dynamics 365 Business Central 2021 Release Wave 1"
      },
      {
        "branches": [
          {
            "category": "product_version_range",
            "name": "<52297",
            "product": {
              "name": "Microsoft Dynamics NAV 2013 R2 <52297",
              "product_id": "11"
            }
          },
          {
            "category": "product_version",
            "name": "52297",
            "product": {
              "name": "Microsoft Dynamics NAV 2013 R2 52297",
              "product_id": "11612"
            }
          }
        ],
        "category": "product_name",
        "name": "Microsoft Dynamics NAV 2013 R2"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2022-41127",
      "notes": [
        {
          "category": "general",
          "text": "Microsoft",
          "title": "Assigning CNA"
        },
        {
          "category": "faq",
          "text": "Yes. An attacker who successfully exploited this vulnerability in Dynamics NAV could execute code on the host server in the context of the service account Dynamics has been configured to use.",
          "title": "According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). Can the exploit move from Dynamics NAV to the underlying operating system?"
        },
        {
          "category": "faq",
          "text": "The attacker must be authenticated to be able to exploit this vulnerability.",
          "title": "According to the CVSS metric, privileges required is low (PR:L).  What does that mean for this vulnerability?"
        },
        {
          "category": "faq",
          "text": "The Dynamics NAV opened port could be used to connect with the WCF TCP protocol. As an authenticated user, the attacker could attempt to trigger malicious code in the context of the server's account through a network call.",
          "title": "According to the CVSS metric, the attack vector is network (AV:N). What is the target used in the context of the remote code execution?"
        },
        {
          "category": "faq",
          "text": "Successful exploitation of this vulnerability requires an attacker to prepare the target environment to improve exploit reliability.",
          "title": "According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?"
        }
      ],
      "product_status": {
        "fixed": [
          "11602",
          "11603",
          "11612",
          "11746",
          "11747",
          "11750",
          "11751",
          "11859",
          "11860",
          "12109",
          "12122",
          "12123",
          "12132"
        ],
        "known_affected": [
          "1",
          "2",
          "3",
          "4",
          "5",
          "6",
          "7",
          "8",
          "9",
          "10",
          "11",
          "12",
          "13"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "CVE-2022-41127 Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability - HTML",
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41127"
        },
        {
          "category": "self",
          "summary": "CVE-2022-41127 Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability - CSAF",
          "url": "https://msrc.microsoft.com/csaf/advisories/2022/msrc_cve-2022-41127.json"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2022-12-13T08:00:00.000Z",
          "details": "Build 52203:Security Update:https://support.microsoft.com/en-us/help/5005293",
          "product_ids": [
            "13"
          ],
          "url": "https://support.microsoft.com/en-us/help/5005293"
        },
        {
          "category": "vendor_fix",
          "date": "2022-12-13T08:00:00.000Z",
          "details": "Build 30712:Security Update:https://support.microsoft.com/en-us/help/5010202",
          "product_ids": [
            "12"
          ],
          "url": "https://support.microsoft.com/en-us/help/5010202"
        },
        {
          "category": "vendor_fix",
          "date": "2022-12-13T08:00:00.000Z",
          "details": "Build 49497:Security Update:https://support.microsoft.com/en-us/help/5021668",
          "product_ids": [
            "10"
          ],
          "url": "https://support.microsoft.com/en-us/help/5021668"
        },
        {
          "category": "vendor_fix",
          "date": "2022-12-13T08:00:00.000Z",
          "details": "52204:Security Update:https://Released Cumulative Updates for Microsoft Dynamics NAV 2015 - Microsoft Support",
          "product_ids": [
            "9"
          ],
          "url": "https://Released Cumulative Updates for Microsoft Dynamics NAV 2015 - Microsoft Support"
        },
        {
          "category": "vendor_fix",
          "date": "2022-12-13T08:00:00.000Z",
          "details": "App Build 14.43.49498, Platform Build 14.0.49494:Security Update:https://support.microsoft.com/en-us/help/5021669",
          "product_ids": [
            "8"
          ],
          "url": "https://support.microsoft.com/en-us/help/5021669"
        },
        {
          "category": "vendor_fix",
          "date": "2022-12-13T08:00:00.000Z",
          "details": "App Build 15.17.48428, Platform Build 15.0.48:Security Update:https://support.microsoft.com/en-us/help/5001733",
          "product_ids": [
            "7"
          ],
          "url": "https://support.microsoft.com/en-us/help/5001733"
        },
        {
          "category": "vendor_fix",
          "date": "2022-12-13T08:00:00.000Z",
          "details": "App Build 17.17.38111, Platform Build 17.0.38061:Security Update:https://support.microsoft.com/en-us/help/5013420",
          "product_ids": [
            "6"
          ],
          "url": "https://support.microsoft.com/en-us/help/5013420"
        },
        {
          "category": "vendor_fix",
          "date": "2022-12-13T08:00:00.000Z",
          "details": "App Build 16.19.35126, Platform Build 16.35120:Security Update:https://support.microsoft.com/en-us/help/5010910",
          "product_ids": [
            "5"
          ],
          "url": "https://support.microsoft.com/en-us/help/5010910"
        },
        {
          "category": "vendor_fix",
          "date": "2022-12-13T08:00:00.000Z",
          "details": "App Build 20.8.49971, Platform Build 20.0.49947:Security Update:https://support.microsoft.com/en-us/help/5021671",
          "product_ids": [
            "3"
          ],
          "url": "https://support.microsoft.com/en-us/help/5021671"
        },
        {
          "category": "vendor_fix",
          "date": "2022-12-13T08:00:00.000Z",
          "details": "App Build 19.14.49970, Platform Build 19.0.49925:Security Update:https://support.microsoft.com/en-us/help/5021670",
          "product_ids": [
            "2"
          ],
          "url": "https://support.microsoft.com/en-us/help/5021670"
        },
        {
          "category": "vendor_fix",
          "date": "2022-12-13T08:00:00.000Z",
          "details": "App Build 21.2.49990, Platform Build 21.0.49984:Security Update:https://support.microsoft.com/en-us/help/5021672",
          "product_ids": [
            "4"
          ],
          "url": "https://support.microsoft.com/en-us/help/5021672"
        },
        {
          "category": "vendor_fix",
          "date": "2022-12-13T08:00:00.000Z",
          "details": "App Build 18.18.46920, Platform Build 18.0.46905:Security Update:https://support.microsoft.com/en-us/help/5019239",
          "product_ids": [
            "1"
          ],
          "url": "https://support.microsoft.com/en-us/help/5019239"
        },
        {
          "category": "vendor_fix",
          "date": "2022-12-13T08:00:00.000Z",
          "details": "52297:Security Update:https://support.microsoft.com/en-us/topic/released-cumulative-updates-for-microsoft-dynamics-nav-2013-r2-c7f39bba-e9b2-51ac-5028-0a31b1ed6996",
          "product_ids": [
            "11"
          ],
          "url": "https://support.microsoft.com/en-us/topic/released-cumulative-updates-for-microsoft-dynamics-nav-2013-r2-c7f39bba-e9b2-51ac-5028-0a31b1ed6996"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "environmentalsScore": 0.0,
            "exploitCodeMaturity": "UNPROVEN",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "remediationLevel": "OFFICIAL_FIX",
            "reportConfidence": "CONFIRMED",
            "scope": "CHANGED",
            "temporalScore": 7.4,
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C",
            "version": "3.1"
          },
          "products": [
            "1",
            "2",
            "3",
            "4",
            "5",
            "6",
            "7",
            "8",
            "9",
            "10",
            "11",
            "12",
            "13"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Remote Code Execution"
        },
        {
          "category": "exploit_status",
          "details": "Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely"
        }
      ],
      "title": "Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability"
    }
  ]
}