-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
                         AUSCERT Security Bulletin

                               ASB-2019.0279
                  Security update for Microsoft Dynamics
                              9 October 2019

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:              Microsoft Dynamics
Operating System:     Windows
Impact/Access:        Cross-site Scripting -- Remote with User Interaction
Resolution:           Patch/Upgrade
CVE Names:            CVE-2019-1375  
Member content until: Friday, November  8 2019

OVERVIEW

        Microsoft has released its monthly security patch update for the month of October 2019.
        
        This update resolves 1 vulnerabilities across the following products: [1]
        
         Microsoft Dynamics 365 (on-premises) version 9.0


IMPACT

        Microsoft has given the following details regarding these vulnerabilities.
        
         Details         Impact                   Severity
         CVE-2019-1375   Spoofing                 Important


MITIGATION

        Microsoft recommends updating the software with the version made available on the Microsoft Update Catalogue for the following Knowledge Base articles. [1].
        
        
         KB4515519


REFERENCES

        [1] Security Update Guide
            https://portal.msrc.microsoft.com/en-US/security-guidance

AusCERT has made every effort to ensure that the information contained
in this document is accurate.  However, the decision to use the information
described is the responsibility of each user or organisation. The decision to
follow or act on information or advice contained in this security bulletin is
the responsibility of each user or organisation, and should be considered in
accordance with your organisation's site policies and procedures. AusCERT
takes no responsibility for consequences which may arise from following or
acting on information or advice contained in this security bulletin.

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours 
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBXZ1u52aOgq3Tt24GAQi7txAA1tQupxad/r+jHeEr0ggANFnWX0AD10zZ
jrXobEJO/K1dqGZFQxSPKG5maG3ZUB4h16BK/DvlUMK3om3GZVaN/igQOq0PyU41
nTGYhMFcvlsCHSfx4DWpb3M/LFQXqlChnR7Bn6HozPYyGNYY2YlONm4rG7YZNcI/
b7FNorwWZ9Ws7zVw/l2XXycQ/RF2h6qb1jIMzbQ6vMDL0YuoDc5mqJLtBawLpi7+
LTixVdei48knpAY47rde9cUh7PEk6ECUCz4/4RNF26YNpdiP1nVIecWIlPYAJcju
YGKQa9aqcj1JDKcdY4R7QYbctujdRKSpMSyACJe21AoOMM2wS2CwHnyGY4JyCvxN
OvvQnrrTFdNPZ3I9PK+a9X3KTd4VB2qNl5dkHYzDWzp6pW0n7+qWAsfTSC5CpqEv
nVeJG7tkalnhWVsNZD9egqZWnyIJsLlcNlO+6JqxDxniHwCBMfOt12iyRSzMHTOL
oN0hENKsTZvudZa+QEEBs3fbk1Tdb+syYYfyxyrgLxeR3p13GC4aqIFNF1aLKdZn
fG/8dCUvS0sXZbx5NSjuLj7HAUdlnCgPIYQDxUE4Qh2+Uk2Yj5NCwigGSJdba9wW
XwKJlx4A6Hccd5koBwt8XTafrGHZIp5oX0QCC3QmVLiii65cAratNym6rhkfU63E
DN3ZjEyyreY=
=IpaV
-----END PGP SIGNATURE-----