Microsoft M365 Copilot是美国微软(Microsoft)公司的一个AI驱动的生产力工具。 Microsoft M365 Copilot存在访问控制错误漏洞。攻击者利用该漏洞执行欺骗攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Microsoft | Microsoft 365 Copilot for Android | 1.0< 16.0.19822.20190 |
affected |
| Microsoft | Microsoft Excel for Android | 16.0.0.0< 16.0.19822.20190 |
affected |
| Microsoft | Microsoft Loop for Android | 1.0.0< 16.0.19822.20190 |
affected |
| Microsoft | Microsoft OneNote for Android | 16.0.1< 16.0.19822.20190 |
affected |
| Microsoft | Microsoft PowerPoint for Android | 16.0.0.0< 16.0.19822.20190 |
affected |
| Microsoft | Microsoft Word for Android | 16.0.0.0< 16.0.19822.20190 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Microsoft | Microsoft 365 Copilot for Android | 1.0 ~ 16.0.19822.20190 | - |
|
| Microsoft | Microsoft Excel for Android | 16.0.0.0 ~ 16.0.19822.20190 | - |
|
| Microsoft | Microsoft Loop for Android | 1.0.0 ~ 16.0.19822.20190 | - |
|
| Microsoft | Microsoft OneNote for Android | 16.0.1 ~ 16.0.19822.20190 | - |
|
| Microsoft | Microsoft PowerPoint for Android | 16.0.0.0 ~ 16.0.19822.20190 | - |
|
| Microsoft | Microsoft Word for Android | 16.0.0.0 ~ 16.0.19822.20190 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-42898 | 9.9 CRITICAL | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability |
| CVE-2026-42823 | 9.9 CRITICAL | Azure Logic Apps Elevation of Privilege Vulnerability |
| CVE-2026-41096 | 9.8 CRITICAL | Windows DNS Client Remote Code Execution Vulnerability |
| CVE-2026-41089 | 9.8 CRITICAL | Windows Netlogon Remote Code Execution Vulnerability |
| CVE-2026-40402 | 9.3 CRITICAL | Windows Hyper-V Elevation of Privilege Vulnerability |
| CVE-2026-40379 | 9.3 CRITICAL | Azure Entra ID Spoofing Vulnerability |
| CVE-2026-42833 | 9.1 CRITICAL | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability |
| CVE-2026-33117 | 9.1 CRITICAL | Azure SDK for Java Security Feature Bypass Vulnerability |
| CVE-2026-41103 | 9.1 CRITICAL | Microsoft SSO Plugin for Jira & Confluence Elevation of Privilege Vulnerability |
| CVE-2026-41109 | 8.8 HIGH | GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-40403 | 8.8 HIGH | Windows Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-40357 | 8.8 HIGH | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-35436 | 8.8 HIGH | Microsoft Office Click-To-Run Elevation of Privilege Vulnerability |
| CVE-2026-35439 | 8.8 HIGH | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-40420 | 8.8 HIGH | Microsoft Office Click-To-Run Elevation of Privilege Vulnerability |
| CVE-2026-41086 | 8.8 HIGH | Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability |
| CVE-2026-41094 | 8.8 HIGH | Microsoft Data Formulator Remote Code Execution Vulnerability |
| CVE-2026-33112 | 8.8 HIGH | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-34329 | 8.8 HIGH | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
| CVE-2026-40365 | 8.8 HIGH | Microsoft SharePoint Server Remote Code Execution Vulnerability |
Showing top 20 of 125 CVEs. View all on vendor page → →
No comments yet