6.2
CVE-2026-41614
- EPSS 0.04%
- Veröffentlicht 12.05.2026 16:58:57
- Zuletzt bearbeitet 14.05.2026 14:25:16
- Quelle secure@microsoft.com
- CVE-Watchlists
- Unerledigt
M365 Copilot for Desktop Spoofing Vulnerability
Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ 365 Copilot SwPlatformwindows Version < 19.2604.43111.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.04% | 0.117 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| secure@microsoft.com | 6.2 | 2.5 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.