{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/dataverse/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_11_21h2:*:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*","cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*","cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2024-38064"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Dataverse"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","cloud-security","vulnerability","high-confidence-source"],"_cs_type":"advisory","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eMicrosoft has disclosed a security vulnerability affecting Microsoft Dataverse, a cloud-based service used to store and manage data for business applications. The vulnerability, tracked as CVE-2024-38064, allows a remote, unauthenticated attacker to perform a privilege escalation attack. Successful exploitation could grant an attacker unauthorized administrative capabilities within the Dataverse environment, leading to data exposure, unauthorized modification, or complete compromise of the affected service instances. Organizations utilizing Dataverse should review their security configurations and monitor for unauthorized administrative actions. As this is a cloud-native vulnerability, mitigation is primarily managed through vendor-applied patches and platform-level security updates.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a high risk to organizations relying on Microsoft Dataverse for business-critical data. If exploited, an attacker could bypass authentication controls to obtain elevated permissions, potentially resulting in full administrative control over Dataverse instances. This impact includes the potential for unauthorized access to sensitive corporate data, manipulation of business logic, and disruption of integrated services that rely on Dataverse for backend storage and operations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the following actions for security and identity teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eReview administrative activity logs in the Microsoft 365 or Power Platform admin centers for unusual activity.\u003c/li\u003e\n\u003cli\u003eImplement the principle of least privilege for all Dataverse service accounts and users.\u003c/li\u003e\n\u003cli\u003eEnsure that Conditional Access policies are strictly enforced for all administrative access to the Power Platform.\u003c/li\u003e\n\u003cli\u003eMonitor vendor security bulletins for further guidance on verifying instance patching for CVE-2024-38064.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T19:46:39Z","date_published":"2026-09-18T19:46:39Z","id":"https://feed.craftedsignal.io/briefs/2026-09-microsoft-dataverse-privesc/","summary":"A vulnerability in Microsoft Dataverse identified as CVE-2024-38064 allows a remote, unauthenticated attacker to escalate privileges and potentially gain administrative access to the service.","title":"Microsoft Dataverse Privilege Escalation Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-09-microsoft-dataverse-privesc/"}],"language":"en","title":"CraftedSignal Threat Feed - Dataverse","version":"https://jsonfeed.org/version/1.1"}