Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-2257 | Server-Side Request Forgery (SSRF) in Microsoft Dynamics 365 Sales allows an authorized attacker to elevate privileges over a network. |
Fri, 13 Feb 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Server-Side Request Forgery (SSRF) in Microsoft Dynamics 365 Sales allows an authorized attacker to elevate privileges over a network. | Server-side request forgery (ssrf) in Microsoft Dynamics 365 Sales allows an authorized attacker to elevate privileges over a network. |
Wed, 17 Dec 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:microsoft:dynamics_365_sales:*:*:*:*:*:*:*:* |
Tue, 11 Feb 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft dynamics 365 Sales |
|
| CPEs | cpe:2.3:a:microsoft:dynamics_365_sales:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Microsoft
Microsoft dynamics 365 Sales |
Fri, 07 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 06 Feb 2025 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Server-Side Request Forgery (SSRF) in Microsoft Dynamics 365 Sales allows an authorized attacker to elevate privileges over a network. | |
| Title | Microsoft Dynamics 365 Sales Elevation of Privilege Vulnerability | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-02-13T19:44:23.270Z
Reserved: 2024-12-05T21:43:30.761Z
Link: CVE-2025-21177
Updated: 2025-02-07T15:58:46.116Z
Status : Analyzed
Published: 2025-02-06T23:15:08.573
Modified: 2025-02-11T22:19:45.057
Link: CVE-2025-21177
No data.
OpenCVE Enrichment
No data.
EUVD