Microsoft 365 Copilot Vulnerabilities Advisory
Summary
CERT-Bund has issued an advisory regarding multiple vulnerabilities in Microsoft 365 Copilot, with a CVSS base score of 8.9. These vulnerabilities could allow remote attackers to disclose information, manipulate data, and gain elevated privileges. Mitigation measures are available.
What changed
CERT-Bund has released an advisory (WID-SEC-2026-0795) detailing multiple critical vulnerabilities affecting Microsoft 365 Copilot and Microsoft 365 Copilot BizChat. The vulnerabilities have a high CVSS base score of 8.9 and a temporal score of 7.7. Exploitation could lead to unauthorized information disclosure, data manipulation, and privilege escalation.
Organizations utilizing Microsoft 365 Copilot should review the advisory and implement available mitigation strategies to protect their systems. The advisory indicates that remote attacks are possible, and prompt action is recommended to address the security risks associated with these vulnerabilities.
What to do next
- Review CERT-Bund advisory WID-SEC-2026-0795 for detailed vulnerability information.
- Implement available mitigation measures for Microsoft 365 Copilot.
- Assess potential impact of vulnerabilities on data confidentiality and integrity.
Source document (simplified)
[WID-SEC-2026-0795] Microsoft 365 Copilot: Mehrere Schwachstellen CVSS Base Score 8.9 (hoch) CVSS Temporal Score 7.7 (hoch) Remoteangriff ja Datum 19.03.2026 Stand 20.03.2026 Mitigation ja
Betroffene Systeme
Betriebssystem
- Sonstiges
- Windows
Produktbeschreibung
Microsoft Copilot ist ein KI-Assistent, der in verschiedene Microsoft-Produkte integriert werden kann.
Produkte
19.03.2026
- Microsoft 365 Copilot
- Microsoft 365 Copilot BizChat
Angriff
Angriff
Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Microsoft 365 Copilot ausnutzen, um Informationen offenzulegen, Daten zu manipulieren und erweiterte Berechtigungen zu erlangen. CVE Informationen Versionshistorie Feedback zum Advisory geben
Related changes
Source
Classification
Who this affects
Taxonomy
Browse Categories
Get Data Privacy & Cybersecurity alerts
Weekly digest. AI-summarized, no noise.
Free. Unsubscribe anytime.
Get alerts for this source
We'll email you when CERT-Bund Security Advisories publishes new changes.