9.6
CVE-2026-41615
- EPSS 0.1%
- Veröffentlicht 14.05.2026 17:00:38
- Zuletzt bearbeitet 15.05.2026 18:39:39
- Quelle secure@microsoft.com
- CVE-Watchlists
- Unerledigt
Microsoft Authenticator Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Authenticator SwPlatformiphone_os Version < 6.8.47
Microsoft ≫ Authenticator SwPlatformandroid Version < 6.2605.2973
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.1% | 0.273 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.4 | 2.8 | 4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
|
| secure@microsoft.com | 9.6 | 2.8 | 6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.