Microsoft

365 Copilot

28 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 0.36%
  • Veröffentlicht 09.06.2026 17:17:20
  • Zuletzt bearbeitet 23.07.2026 08:10:00

Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.

Medienbericht
  • EPSS 0.39%
  • Veröffentlicht 09.06.2026 17:17:20
  • Zuletzt bearbeitet 23.07.2026 08:10:00

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Medienbericht
  • EPSS 0.36%
  • Veröffentlicht 09.06.2026 17:17:20
  • Zuletzt bearbeitet 23.07.2026 08:10:00

Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information locally.

  • EPSS 0.45%
  • Veröffentlicht 04.06.2026 22:00:49
  • Zuletzt bearbeitet 23.07.2026 07:10:00

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute code over a network.

Medienbericht
  • EPSS 7.64%
  • Veröffentlicht 04.06.2026 22:00:49
  • Zuletzt bearbeitet 23.07.2026 07:10:00

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

  • EPSS 0.42%
  • Veröffentlicht 22.05.2026 22:03:09
  • Zuletzt bearbeitet 23.07.2026 11:10:00

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.

  • EPSS 0.5%
  • Veröffentlicht 22.05.2026 22:03:08
  • Zuletzt bearbeitet 23.07.2026 11:10:00

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Medienbericht
  • EPSS 0.36%
  • Veröffentlicht 12.05.2026 16:58:57
  • Zuletzt bearbeitet 14.05.2026 14:25:16

Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally.

Medienbericht
  • EPSS 0.25%
  • Veröffentlicht 12.05.2026 16:58:53
  • Zuletzt bearbeitet 16.05.2026 01:49:18

Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally.

  • EPSS 0.4%
  • Veröffentlicht 23.04.2026 21:35:48
  • Zuletzt bearbeitet 29.04.2026 19:04:21

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.