Microsoft published security advisories for two spoofing vulnerabilities affecting business communication platforms: CVE-2024-49053 in Microsoft Dynamics 365 Sales and CVE-2025-47977 in the Nuance Digital Engagement Platform. Both issues were listed in the Microsoft Security Update Guide as spoofing flaws, indicating a risk that attackers could impersonate trusted users, services, or communications within affected environments.
The advisories point to separate Microsoft product lines but a common security concern for organizations that rely on customer engagement and sales workflows. Security teams using Dynamics 365 Sales or Nuance Digital Engagement should review the relevant Microsoft guidance, determine exposure in their deployments, and apply available updates or mitigations to reduce the risk of fraudulent interactions and trust-based attacks.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft added CVE-2025-47977, a Nuance Digital Engagement Platform spoofing vulnerability, to its Security Update Guide.
Microsoft added CVE-2024-49053, a Microsoft Dynamics 365 Sales spoofing vulnerability, to its Security Update Guide.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.