Microsoft 365 Word Copilot是美国Microsoft公司的一个AI助手。 Microsoft 365 Word Copilot存在命令注入漏洞,该漏洞源于容易受到欺骗攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Microsoft | Microsoft 365 Word Copilot | - | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-59246 | 9.8 CRITICAL | Azure Entra ID Elevation of Privilege Vulnerability |
| CVE-2025-59218 | 9.6 CRITICAL | Azure Entra ID Elevation of Privilege Vulnerability |
| CVE-2025-59286 | 9.3 CRITICAL | Copilot Information Disclosure Vulnerability |
| CVE-2025-59272 | 9.3 CRITICAL | Copilot Information Disclosure Vulnerability |
| CVE-2025-55321 | 9.3 CRITICAL | Azure Monitor Log Analytics Spoofing Vulnerability |
| CVE-2025-59247 | 8.8 HIGH | Azure PlayFab Elevation of Privilege Vulnerability |
| CVE-2025-59271 | 8.7 HIGH | Redis Enterprise Elevation of Privilege Vulnerability |
No comments yet