Vulnerabilities
Vulnerable Software
Microsoft:  >> 365 Copilot  Security Vulnerabilities
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVSS Score
5.3
EPSS Score
0.006
Published
2026-03-19
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVSS Score
7.1
EPSS Score
0.004
Published
2026-03-16
Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVSS Score
7.8
EPSS Score
0.004
Published
2026-03-10
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
CVSS Score
8.4
EPSS Score
0.005
Published
2026-03-10
Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally.
CVSS Score
5.5
EPSS Score
0.007
Published
2026-03-10
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVSS Score
7.0
EPSS Score
0.005
Published
2026-03-10
Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVSS Score
9.3
EPSS Score
0.008
Published
2026-01-22
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVSS Score
8.4
EPSS Score
0.004
Published
2025-12-09
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
CVSS Score
8.4
EPSS Score
0.004
Published
2025-12-09
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVSS Score
7.8
EPSS Score
0.008
Published
2025-11-11


Contact Us

Shodan ® - All rights reserved