VYPR

365 Copilot

by Microsoft

CVEs (48)

  • CVE-2023-23391MedMar 14, 2023
    risk 0.36cvss 5.5epss 0.01

    Office for Android Spoofing Vulnerability

  • CVE-2026-24299MedMar 19, 2026
    risk 0.35cvss 5.3epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-41100MedMay 12, 2026
    risk 0.29cvss 4.4epss 0.00

    Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally.

  • CVE-2026-50517CriJul 24, 2026
    risk 0.00cvss 9.9epss 0.01

    Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

  • CVE-2026-58617HigJul 14, 2026
    risk 0.00cvss 8.1epss 0.01

    Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-50387HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.02

    Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.

  • CVE-2026-48561CriJul 14, 2026
    risk 0.00cvss 9.6epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-41106CriJul 2, 2026
    risk 0.00cvss 9.3epss 0.01

    Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

Page 3 of 3