Skip to content
Threat Feed
high advisory

Microsoft Dataverse Privilege Escalation Vulnerability

A vulnerability in Microsoft Dataverse identified as CVE-2024-38064 allows a remote, unauthenticated attacker to escalate privileges and potentially gain administrative access to the service.

CVE search metadata

CVE search record: CVE-2024-38064. Severity: high. CVSS: 7.5. EPSS: 2.20%. KEV: no. Product: Dataverse. Brief: Microsoft Dataverse Privilege Escalation Vulnerability. Brief link: https://feed.craftedsignal.io/briefs/2026-09-microsoft-dataverse-privesc/

Microsoft has disclosed a security vulnerability affecting Microsoft Dataverse, a cloud-based service used to store and manage data for business applications. The vulnerability, tracked as CVE-2024-38064, allows a remote, unauthenticated attacker to perform a privilege escalation attack. Successful exploitation could grant an attacker unauthorized administrative capabilities within the Dataverse environment, leading to data exposure, unauthorized modification, or complete compromise of the affected service instances. Organizations utilizing Dataverse should review their security configurations and monitor for unauthorized administrative actions. As this is a cloud-native vulnerability, mitigation is primarily managed through vendor-applied patches and platform-level security updates.

Impact

The vulnerability poses a high risk to organizations relying on Microsoft Dataverse for business-critical data. If exploited, an attacker could bypass authentication controls to obtain elevated permissions, potentially resulting in full administrative control over Dataverse instances. This impact includes the potential for unauthorized access to sensitive corporate data, manipulation of business logic, and disruption of integrated services that rely on Dataverse for backend storage and operations.

Recommendation

Prioritize the following actions for security and identity teams:

  • Review administrative activity logs in the Microsoft 365 or Power Platform admin centers for unusual activity.
  • Implement the principle of least privilege for all Dataverse service accounts and users.
  • Ensure that Conditional Access policies are strictly enforced for all administrative access to the Power Platform.
  • Monitor vendor security bulletins for further guidance on verifying instance patching for CVE-2024-38064.

Immediate actions

Review Power Platform and Dataverse audit logs for anomalous administrative behavior.

SOC 24h

Mitigations

Verify current patch status of Dataverse instances via the Microsoft 365 admin center.

immediate IT Operations

CVE-2024-38064