Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT Security Bulletin ASB-2018.0299 Microsoft Dynamics updates for December 2018 12 December 2018 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: Microsoft Dynamics 365 (on-premises) Microsoft Dynamics NAV Operating System: Windows Impact/Access: Cross-site Scripting -- Remote with User Interaction Resolution: Patch/Upgrade CVE Names: CVE-2018-8651 Member content until: Friday, January 11 2019 Reference: ASB-2018.0283 OVERVIEW Microsoft has released its monthly security patch update for the month of December 2018. This update resolves 6 vulnerabilities across the following products: [1] Microsoft Dynamics 365 (on-premises) version 8 Microsoft Dynamics NAV 2016 Microsoft Dynamics NAV 2017 IMPACT Microsoft has given the following details regarding this vulnerability. Details Impact Severity CVE-2018-8651 Spoofing Important MITIGATION Microsoft recommends updating the software with the version made available on the Microsoft Update Catalogue for the following Knowledge Base articles. [1]. KB4479232, KB4479233 REFERENCES [1] Security Update Guide https://portal.msrc.microsoft.com/en-us/security-guidance AusCERT has made every effort to ensure that the information contained in this document is accurate. However, the decision to use the information described is the responsibility of each user or organisation. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBXBBJP2aOgq3Tt24GAQjoKg//S9pNjazeUH9XjxbleeXFAe7nG3KS7OMi IwpWUr9ZjdGkZul2xyRfS+frprfqV7Xhd0qqxdln8b+qG1GQ0RzIyo2XpcKDw3qd ukaC+gl9fmkpkcUQXEniu8cHrDDNhZTTraKskS5+ESfYq8Ukl2De9uXnTxHj5pV1 U1lHUJVbNdYalRaWVIxnT33ueNrKO9xzWPiqIkkiTZ6RcyS/2ZwS4zM/lGXDEeMv LotzNHItGqYssdMkT+JBbCfrXtkpqoGH3axw4uys2V1c3MydeGaRsK3EAKBIU15X SaVAmHqElrbkCseFa8ZEnBDA3Ue0gYpSR1KLUP5FuwMi+Z+VKDCJl7tthbuervyT pffr4QxlHlcGcP9OeN1KbVhYBFuxPYWU8apErRDWfsUQe8fzPDsmMXFRM63t6GR7 EsyY/LR7EzhnwPTPR6F35y1jgwqxn43S2ZMQpraWAv1wOAvORhJeZ9mfuemIXvoz c9mHv7ujoNCzZ7818EhuqJwiSmZXUzuIYc5tV5du/dnXROEThimOyCPoNVM5jCLs 0SsmhlVkViG8VmJuTWPTPnl/TjjCtJTFotl2amnxz0nAayTjz9hC8A15UntuhdrF CLaq3arJ1OySdHAdu6j03eOWU/cbs1yQnRZ+wJ/uur/O0XlEjFo4/xw7sMENoUBJ IeCUhlOPW1w= =dQYM -----END PGP SIGNATURE-----