« Volver al listado

Microsoft

Microsoft Power Automate FOR Desktop: vulnerabilidades y CVE

Microsoft Power Automate FOR Desktop tiene 5 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE5
Últimos 12 meses2
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-77897Alta (7)0.28%—8 sept 2026
Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally.
CVE-2026-40374Media (6.5)1.00%—12 may 2026
Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose information over a network.
CVE-2025-47966Crítica (9.8)1.2%—5 jun 2025
Exposure of sensitive information to an unauthorized actor in Power Automate allows an unauthorized attacker to elevate privileges over a network.
CVE-2025-29817Media (5.7)0.90%—15 abr 2025
Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network.
CVE-2025-21187Alta (7.8)0.75%—14 ene 2025
Microsoft Power Automate Remote Code Execution Vulnerability

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1005 Data from Local System2
  2. T1059 Command and Scripting Interpreter1
  3. T1068 Exploitation for Privilege Escalation1
  4. T1190 Exploit Public-Facing Application1
  5. T1203 Exploitation for Client Execution1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

📰 Noticias relacionadas

Otros productos de Microsoft