CVE-2018-8609: Microsoft Dynamics 365

High severity, CVSS 8.8. EPSS: 9.9% chance of exploitation in the next 30 days.

A remote code execution vulnerability exists in Microsoft Dynamics 365 (on-premises) version 8 when the server fails to properly sanitize web requests to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Remote Code Execution Vulnerability." This affects Microsoft Dynamics 365.

Affected products

  • Microsoft Dynamics 365: from 8.0, before 8.2.3.0003 (fixed in 8.2.3.0003)

Published 2018-11-14. Last modified 2026-06-17.