External risk intelligence

Microsoft Dataverse Untrusted Search Path Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2024-35260

Microsoft Dataverse is a cloud-based platform service. While it can be configured for external connectivity, it is typically accessed by authenticated users within an organization's business environment. Public internet reachability depends heavily on specific application-level configurations and access policies, making it plausible but not inherently public-facing by default.

Microsoft Power Platform

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical vulnerability in Microsoft Dataverse that could allow an authenticated attacker to remotely execute code. The concern is centered on the potential for unauthorized code execution within the affected technology, which may impact business operations if exploited. The primary focus should be on confirming if your organization utilizes this technology and assessing potential exposure.

  • Flaw allows remote code execution by attackers.
  • Critical flaw could impact business operations.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker with valid credentials can exploit a flaw in Microsoft Dataverse that allows for an untrusted search path. This could enable the attacker to execute code remotely over a network, potentially leading to a complete system compromise.

  • Requires authenticated access to Microsoft Dataverse.
  • Exploits an untrusted search path vulnerability.
  • Enables unauthenticated remote code execution.

Live Threat

Current exploitation, exposure, and threat context

An authenticated attacker could execute code over a network by exploiting a flaw in Microsoft Dataverse's handling of untrusted search paths. This could allow unauthorized code execution on systems that host or interact with Dataverse services.

  • Code execution on the server.
  • Exploiting untrusted search paths.
  • Unauthorized access and control.

Operational Fix

Recommended remediation, mitigation, and detection steps

Real-World Ownership:

Exploiting this vulnerability requires authenticated access to Microsoft Dataverse, making application owners and potentially platform teams responsible for identifying and mitigating the risk. The initial practical move is to confirm the presence of the affected technology, determine its exposure, and identify the accountable business owner to plan remediation.

  • Application and platform teams own remediation.
  • Verify Dataverse reachability and business criticality.
  • Plan risk-based remediation with accountable owners.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Microsoft Power Platform and Dataverse?

Microsoft Power Platform is a suite of low-code tools for building business applications and workflows. Microsoft Dataverse acts as the secure, cloud-based data storage and service layer within this platform. It enables organizations to store, manage, and model business data used across applications, effectively serving as the backend engine that connects various business processes and intelligence tools.

What does an untrusted search path vulnerability mean for CVE-2024-35260?

This vulnerability is classified as CWE-426, which occurs when a program searches for a resource in an insecure location. An attacker can manipulate this search path to force the system to load or execute a malicious file instead of the legitimate component. In the context of CVE-2024-35260, this flaw allows an attacker to run arbitrary code by tricking the system into using unauthorized code during its standard operations.

How does an attacker trigger this vulnerability?

To trigger this, an attacker must have existing authenticated access to the Microsoft Dataverse environment. They leverage this access to influence the search path the system uses when looking for resources. It is important to note that this is not a blind internet attack; simply reaching the service over a network is not sufficient to trigger the flaw without the required authentication credentials.

Do I need to worry if my Dataverse instance is not public?

Halo Surface Signal indicates that while Dataverse is a cloud service, its public reachability depends on your specific application-level configurations and policies. Even if your instance is not explicitly open to the public internet, it may still be accessible to internal users. Since the vulnerability requires authenticated access, any user with credentials—even internal ones—could potentially exploit the flaw.

What should I do first to manage this risk?

Begin by confirming if your organization utilizes Microsoft Power Platform and its Dataverse services. Once you verify its presence, coordinate with your platform and application teams to determine who owns the business instance. Your goal is to assess the specific reachability of your implementation and work with the accountable business owner to prioritize and implement security updates provided by Microsoft.

References