This post has been republished via RSS; it originally appeared at: MSRC Security Update Guide.
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.