VYPR

365 Copilot

by Microsoft

CVEs (48)

  • CVE-2025-30386HigMay 13, 2025
    risk 0.55cvss 8.4epss 0.01

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2026-42831HigMay 12, 2026
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2026-26134HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally.

  • CVE-2025-62199HigNov 11, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-59234HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.01

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-59227HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-53732HigAug 12, 2025
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-49702HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.01

    Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-30388HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.04

    Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.

  • CVE-2024-38250HigSep 10, 2024
    risk 0.51cvss 7.8epss 0.01

    Windows Graphics Component Elevation of Privilege Vulnerability

  • CVE-2025-26687HigApr 8, 2025
    risk 0.49cvss 7.5epss 0.01

    Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-26133HigMar 16, 2026
    risk 0.46cvss 7.1epss 0.00

    AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-24285HigMar 10, 2026
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

  • CVE-2023-36565HigOct 10, 2023
    risk 0.46cvss 7.0epss 0.00

    Microsoft Office Graphics Elevation of Privilege Vulnerability

  • CVE-2026-42895MedJun 19, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.

  • CVE-2026-42824MedJun 4, 2026
    risk 0.42cvss 6.5epss 0.08

    Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-42827MedMay 22, 2026
    risk 0.42cvss 6.5epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-41614MedMay 12, 2026
    risk 0.40cvss 6.2epss 0.00

    Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally.

  • CVE-2026-25180MedMar 10, 2026
    risk 0.36cvss 5.5epss 0.01

    Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally.

  • CVE-2025-53799MedSep 9, 2025
    risk 0.36cvss 5.5epss 0.01

    Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally.