Microsoft M365 Copilot是美国微软(Microsoft)公司的一个AI驱动的生产力工具。 Microsoft M365 Copilot存在安全漏洞,该漏洞源于对指定类型的输入验证不当。攻击者利用该漏洞可以通过网络泄露信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Microsoft | Microsoft 365 Copilot | - |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Microsoft | Microsoft 365 Copilot | - | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-24306 | 9.8 CRITICAL | Azure Front Door Elevation of Privilege Vulnerability |
| CVE-2026-21264 | 9.3 CRITICAL | Microsoft Account Spoofing Vulnerability |
| CVE-2026-24305 | 9.3 CRITICAL | Azure Entra ID Elevation of Privilege Vulnerability |
| CVE-2026-21227 | 8.2 HIGH | Azure Logic Apps Elevation of Privilege Vulnerability |
| CVE-2026-21520 | 7.5 HIGH | Copilot Studio Information Disclosure Vulnerability |
| CVE-2026-21521 | 7.4 HIGH | Word Copilot Information Disclosure Vulnerability |
| CVE-2026-21524 | 7.4 HIGH | Azure Data Explorer Information Disclosure Vulnerability |
No comments yet