Dynamics 365 Business Central: User experience - Preview images directly in web client

🚨 The Signal: Dynamics 365 Business Central now allows direct image preview in the web client, reducing the need for downloads. This change introduces new attack vectors for malicious content delivery and user compromise through embedded images.

The Impact

All Business Central users are affected, facing increased risk from embedded malicious images and potential client-side exploits.

  • End users: Increased risk of malware infection from viewing malicious images.
  • Security teams: New vector for client-side exploits and content-based attacks.
  • Developers: Must implement secure viewing methods for extensions, or risk vulnerabilities.
  • Admins: Need to review content filtering and endpoint protection strategies.

The Action

  1. Review and update endpoint detection and response (EDR) policies to detect image-based threats.
  2. Educate users on the risks of viewing untrusted image attachments, even in preview.
  3. Advise developers to use File.ViewFromStream securely, validating image content.
  4. Implement content disarm and reconstruction (CDR) solutions for Business Central attachments if not already in place.
  5. Regularly audit Business Central extensions for secure image handling practices.

Domain: Other · Impact: high · Workload: Other · Essential Eight: User Application Hardening · ISM: ISM-1412, ISM-1485, ISM-1486, ISM-1542, ISM-1585, ISM-1667, ISM-1668, ISM-1669, ISM-1670, ISM-1823, ISM-1824, ISM-1859, ISM-1860