Vulnerabilities
Vulnerable Software
Microsoft:  >> 365 Copilot  Security Vulnerabilities
Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information locally.
CVSS Score
4.7
EPSS Score
0.004
Published
2026-06-09
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVSS Score
8.4
EPSS Score
0.004
Published
2026-06-09
Integer underflow (wrap or wraparound) in Microsoft Office allows an unauthorized attacker to execute code locally.
CVSS Score
8.4
EPSS Score
0.004
Published
2026-06-09
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVSS Score
6.5
EPSS Score
0.005
Published
2026-05-22
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.
CVSS Score
9.3
EPSS Score
0.004
Published
2026-05-22
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVSS Score
7.8
EPSS Score
0.004
Published
2026-05-12
Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally.
CVSS Score
6.2
EPSS Score
0.004
Published
2026-05-12
Improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally.
CVSS Score
4.4
EPSS Score
0.002
Published
2026-05-12
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVSS Score
8.4
EPSS Score
0.004
Published
2026-05-12
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
9.3
EPSS Score
0.004
Published
2026-04-23


Contact Us

Shodan ® - All rights reserved