Microsoft Copilot是美国微软(Microsoft)公司的一款基于人工智能的辅助工具,提供内容生成、代码编写和办公协作等能力。 Microsoft Copilot存在命令注入漏洞,该漏洞源于命令中特殊元素中和不当,可能导致未经授权的攻击者通过网络泄露信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Microsoft | Microsoft Copilot | - |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Microsoft | Microsoft Copilot | - | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-32169 | 10.0 CRITICAL | Azure Cloud Shell Elevation of Privilege Vulnerability |
| CVE-2026-26137 | 9.9 CRITICAL | Microsoft Exchange Elevation of Privilege Vulnerability |
| CVE-2026-32191 | 9.8 CRITICAL | Microsoft Bing Images Remote Code Execution Vulnerability |
| CVE-2026-32194 | 9.8 CRITICAL | Microsoft Bing Images Remote Code Execution Vulnerability |
| CVE-2026-26139 | 8.6 HIGH | Microsoft Purview Elevation of Privilege Vulnerability |
| CVE-2026-26138 | 8.6 HIGH | Microsoft Purview Elevation of Privilege Vulnerability |
| CVE-2026-23658 | 8.6 HIGH | Azure DevOps: msazure Elevation of Privilege Vulnerability |
| CVE-2026-23659 | 8.6 HIGH | Azure Data Factory Information Disclosure Vulnerability |
| CVE-2026-26120 | 6.5 MEDIUM | Microsoft Bing Tampering Vulnerability |
| CVE-2026-24299 | 5.3 MEDIUM | M365 Copilot Information Disclosure Vulnerability |
No comments yet