« Volver al listado

Microsoft

Microsoft 365 Copilot: vulnerabilidades y CVE

Microsoft 365 Copilot tiene 55 vulnerabilidades publicadas, 36 de ellas en los últimos 12 meses. 9 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE55
Últimos 12 meses36
Críticas9
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-85887Alta (7.7)0.84%—18 sept 2026
Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network.
CVE-2026-85885Alta (8.8)0.72%—17 sept 2026
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.
CVE-2026-78501Alta (7.4)0.89%—17 sept 2026
Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network.
CVE-2026-50517Crítica (9.9)1.7%—24 jul 2026
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
CVE-2026-58617Crítica (9.8)0.79%—14 jul 2026
Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-50387Alta (7.8)0.33%—14 jul 2026
Stack-based buffer overflow in Windows GDI allows an authorized attacker to elevate privileges locally.
CVE-2026-48561Crítica (9.6)0.86%—14 jul 2026
Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network.
CVE-2026-41106Crítica (9.3)0.72%—2 jul 2026
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-47645Alta (8.8)0.76%—19 jun 2026
Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-42895Alta (7.5)0.71%—19 jun 2026
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.
CVE-2026-54130Alta (7.5)1.1%—18 jun 2026
Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2026-45474Alta (8.4)0.36%—9 jun 2026
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-45472Alta (8.4)0.36%—9 jun 2026
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-45463Alta (8.4)0.36%—9 jun 2026
Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-45461Alta (8.4)0.36%—9 jun 2026
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-45460Media (4.7)0.42%—9 jun 2026
Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVE-2026-42827Alta (7.5)0.92%—22 may 2026
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2026-41090Crítica (9.3)0.76%—22 may 2026
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.
CVE-2026-42831Alta (7.8)0.47%—12 may 2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-41614Media (6.2)0.40%—12 may 2026
Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally.
CVE-2026-41100Media (4.4)0.26%—12 may 2026
Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally.
CVE-2026-40363Alta (8.4)0.36%—12 may 2026
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-33102Crítica (9.3)0.72%—23 abr 2026
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-24299Media (5.3)0.65%—19 mar 2026
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2026-26133Alta (7.1)0.54%—16 mar 2026
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2026-26134Alta (7.8)0.33%—10 mar 2026
Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVE-2026-26110Alta (7.8)0.34%—10 mar 2026
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-25180Media (5.5)0.66%—10 mar 2026
Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally.
CVE-2026-24285Alta (7)0.46%—10 mar 2026
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVE-2026-24307Alta (7.5)0.92%—22 ene 2026
Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter2
  2. T1210 Exploitation of Remote Services2
  3. T1203 Exploitation for Client Execution1
  4. T1222 File and Directory Permissions Modification1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Microsoft