Release date:
Updated on:
Affected Systems:
Microsoft Dynamics AX 4.0
Microsoft Dynamics AX 2012 R2
Microsoft Dynamics AX 2012
Microsoft Dynamics AX 2009
Description:
--------------------------------------------------------------------------------
Bugtraq id: 64724
CVE (CAN) ID: CVE-2014-0261
Microsoft Dynamics is a commercial software for enterprises.
Microsoft Dynamics AX has a denial of service vulnerability. If Authenticated Users submit specially crafted data to the affected Microsoft Dynamics AX Application Object Server (AOS) instance, this vulnerability can cause DOS. After successful exploitation, the target AOS instance stops responding to client requests.
<* Source: vendor
Link: http://technet.microsoft.com/security/bulletin/MS14-004
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Microsoft
---------
Microsoft has released a Security Bulletin (MS14-004) and patches for this:
MS14-004: Vulnerability in Microsoft Dynamics AX cocould Allow Denial of Service (2880826)
Link: http://technet.microsoft.com/security/bulletin/MS14-004