-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
                         AUSCERT Security Bulletin

                               ASB-2021.0194
  Microsoft Patch Tuesday update for Microsoft Dynamics for October 2021
                              13 October 2021

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:          Microsoft Dynamics 365 (on-premises)
                  Microsoft Dynamics 365 Customer Engagement
Operating System: Windows
Impact/Access:    Provide Misleading Information -- Remote with User Interaction
Resolution:       Patch/Upgrade
CVE Names:        CVE-2021-41354 CVE-2021-41353 CVE-2021-40457

OVERVIEW

        Microsoft has released its monthly security patch update for the
        month of October 2021.
        
        This update resolves 3 vulnerabilities across the following products:
        [1]
        
         Microsoft Dynamics 365 (on-premises) version 9.0
         Microsoft Dynamics 365 (on-premises) version 9.1
         Microsoft Dynamics 365 Customer Engagement V9.0
         Microsoft Dynamics 365 Customer Engagement V9.1


IMPACT

        Microsoft has given the following details regarding these vulnerabilities.
        
         Details         Impact                   Severity
         CVE-2021-40457  Spoofing                 Important
         CVE-2021-41353  Spoofing                 Important
         CVE-2021-41354  Spoofing                 Important


MITIGATION

        Microsoft recommends updating the software with the version made
        available on the Microsoft Update Catalogue for the following
        Knowledge Base articles. [1].
        
         KB4618795, KB4618810


REFERENCES

        [1] Microsoft Security Update Guidance
            https://portal.msrc.microsoft.com/en-us/security-guidance

AusCERT has made every effort to ensure that the information contained
in this document is accurate.  However, the decision to use the information
described is the responsibility of each user or organisation. The decision to
follow or act on information or advice contained in this security bulletin is
the responsibility of each user or organisation, and should be considered in
accordance with your organisation's site policies and procedures. AusCERT
takes no responsibility for consequences which may arise from following or
acting on information or advice contained in this security bulletin.

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours 
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBYWZsxONLKJtyKPYoAQjQlxAAn/iTwFgDX4YXfZnsP99HDAgjHFMxSG7i
IB9Xl8GfN6HuCA3sEubIj+JkBYF+Z7SmcMAejCuf8LGqquet6oUBVHYGbwmIXPgq
0Lu73BSuM8BOl8qMiZDhuEJFvUfi6EN+uXv8vvfBttXgSzep5Gvizm9gYAjL2XCV
HzgPE5DhicctD9aNDC5boVO9cFb5Bozilgr+dCdSkndrD9ir9SwyNgRfI3utDxB7
egpTIuesljjHqjC1T45OInX3Yveexu942NmUHeRz9rUrAY3WlOSVTAYjyJK/sX9H
1HRS+YDn3whPasKfr3sDjTzcIViQMsU2A58DROgVUwOdVjeKeCdrOqP0cRaOHN7b
CUF7MdfL0A7YLN02PpmErC3F9d1L+z7jNDRidoscRzghf7GIjRt48fwG2V11N0aN
i/sgqLIjecp8GQc14PX2DN8izjfifMqu7F3u4NVwktoeAXJjv9W4K1Y3WndsSg3K
6y09hQ/wALxZHEEt3+BZ6onGrspsZ5qInNGNVpLeokca/MySKtgANPMBvrgWJ6xV
Pibxl38tYWjd5id6KlV4yhw51tBK/wKEPsaPksxVExBxeOEI2OI9jxNhsSKHCnt8
Z6EAaaCqvw/1FEM6XY0fKwLzVIe9JGy8FQIjlMDFrItCIUCKOb3CqfJByQOVp/7+
JL3O67Dk+aQ=
=yt7j
-----END PGP SIGNATURE-----