By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Severe Security Flaws Patched in Microsoft Dynamics 365 and Power Apps Web API
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Severe Security Flaws Patched in Microsoft Dynamics 365 and Power Apps Web API
Tech News

Severe Security Flaws Patched in Microsoft Dynamics 365 and Power Apps Web API

By Viral Trending Content 3 Min Read
Share
SHARE

Jan 02, 2025Ravie LakshmananVulnerability / Data Protection

Microsoft Dynamics 365 and Power Apps Web API

Details have emerged about three now-patched security vulnerabilities in Dynamics 365 and Power Apps Web API that could result in data exposure.

The flaws, discovered by Melbourne-based cybersecurity company Stratus Security, have been addressed as of May 2024. Two of the three shortcomings reside in Power Platform’s OData Web API Filter, while the third vulnerability is rooted in the FetchXML API.

The root cause of the first vulnerability is the lack of access control on the OData Web API Filter, thereby allowing access to the contacts table that holds sensitive information such as full names, phone numbers, addresses, financial data, and password hashes.

Cybersecurity

A threat actor could then weaponize the flaw to perform a boolean-based search to extract the complete hash by guessing each character of the hash sequentially until the correct value is identified.

“For example, we start by sending startswith(adx_identity_passwordhash, ‘a’) then startswith(adx_identity_passwordhash , ‘aa’) then startswith(adx_identity_passwordhash , ‘ab’) and so on until it returns results that start with ab,” Stratus Security said.

“We continue this process until the query returns results that start with ‘ab’. Eventually, when no further characters return a valid result, we know we have obtained the complete value.”

Microsoft Dynamics 365 and Power Apps Web API

The second vulnerability, on the other hand, lies in using the orderby clause in the same API to obtain the data from the necessary database table column (e.g., EMailAddress1, which refers to the primary email address for the contact).

Lastly, Stratus Security also found that the FetchXML API could be exploited in conjunction with the contacts table to access restricted columns using an orderby query.

Cybersecurity

“When utilizing the FetchXML API, an attacker can craft an orderby query on any column, completely bypassing the existing access controls,” it said. “Unlike the previous vulnerabilities, this method does not necessitate the orderby to be in descending order, adding a layer of flexibility to the attack.”

An attacker weaponizing these flaws could, therefore, compile a list of password hashes and emails, then crack the passwords or sell the data.

“The discovery of vulnerabilities in the Dynamics 365 and Power Apps API underscores a critical reminder: cybersecurity requires constant vigilance, especially for large companies that hold so much data like Microsoft,” Stratus Security said.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Anthropic sets sights on small business after enterprise push

Sony Xperia 1 VIII AI Camera Assistant Internet Outrage

How to Control Everything on Your Phone With Your Voice (iOS and Android)

Critical Nginx UI auth bypass flaw now actively exploited in the wild

Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming

TAGGED: Access Control, API Security, Cyber Security, Cybersecurity, data protection, Internet, Microsoft, password security, Vulnerability
Share This Article
Facebook Twitter Copy Link
Previous Article Person in exploded Cybertruck believed to be elite soldier
Next Article First Bitcoin Acquisition By A US State ‘Near Guaranteed’ Within 4 Months: Expert
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Bitcoin Treasury Firm Strategy To Repurchase $1.5B Of Convertible Notes — Details
Crypto
Forza Horizon 6 Lets You Race A Gundam And It Looks Awesome
Gaming News
Hushpitality, inheritourism and US road trips: These are all the 2026 travel trends you need to know
Travel
Good time to fill up on fuel as prices set to jump – Why, and by how much?
World News
Anthropic sets sights on small business after enterprise push
Tech News
Commerzbank axes 3,000 jobs in an attempt to fight off UniCredit takeover bid
Business
AI poised to tilt job market leverage toward older workers
Business

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Forza Horizon 6 Lets You Race A Gundam And It Looks Awesome

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Forza Horizon 6 Lets You Race A Gundam And It Looks Awesome
May 17, 2026
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?