365 Copilot
by Microsoft
CVEs (48)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-23391 | Med | 0.36 | 5.5 | 0.01 | Mar 14, 2023 | Office for Android Spoofing Vulnerability | ||
| CVE-2026-24299 | Med | 0.35 | 5.3 | 0.01 | Mar 19, 2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-41100 | Med | 0.29 | 4.4 | 0.00 | May 12, 2026 | Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally. | ||
| CVE-2026-50517 | Cri | 0.00 | 9.9 | 0.01 | Jul 24, 2026 | Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network. | ||
| CVE-2026-58617 | Hig | 0.00 | 8.1 | 0.01 | Jul 14, 2026 | Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-50387 | Hig | 0.00 | 7.8 | 0.02 | Jul 14, 2026 | Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-48561 | Cri | 0.00 | 9.6 | 0.01 | Jul 14, 2026 | Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-41106 | Cri | 0.00 | 9.3 | 0.01 | Jul 2, 2026 | Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. |
- risk 0.36cvss 5.5epss 0.01
Office for Android Spoofing Vulnerability
- risk 0.35cvss 5.3epss 0.01
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.
- risk 0.29cvss 4.4epss 0.00
Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally.
- risk 0.00cvss 9.9epss 0.01
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
- risk 0.00cvss 8.1epss 0.01
Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.
- risk 0.00cvss 7.8epss 0.02
Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 9.6epss 0.01
Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 9.3epss 0.01
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
Page 3 of 3