Microsoft Microsoft 365 Copilot for iOS, 365 copilot
Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.
The CVSS severity warrants an early asset and exposure review.Use CVSS, EPSS, CISA KEV, affected-version data, and source evidence as separate signals for prioritization.
NVD data is used under its public data terms. This service is not endorsed or certified by NVD.Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.
The CVSS severity warrants an early asset and exposure review.Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
The CVSS severity warrants an early asset and exposure review.Integer overflow or wraparound in Windows RDP allows an unauthorized attacker to execute code over a network.
The CVSS severity warrants an early asset and exposure review.Heap-based buffer overflow in Universal Plug and Play (upnp.dll) allows an authorized attacker to elevate privileges locally.
The CVSS severity warrants an early asset and exposure review.Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
The CVSS severity warrants an early asset and exposure review.Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally.
The CVSS severity warrants an early asset and exposure review.Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally.
The CVSS severity warrants an early asset and exposure review.Improper authorization in Windows Installer allows an authorized attacker to elevate privileges locally.
The CVSS severity warrants an early asset and exposure review.Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
The CVSS severity warrants an early asset and exposure review.Heap-based buffer overflow in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
The CVSS severity warrants an early asset and exposure review.Use after free in Microsoft NAT Helper Components (ipnathlp.dll) allows an authorized attacker to elevate privileges locally.
The CVSS severity warrants an early asset and exposure review.Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
The CVSS severity warrants an early asset and exposure review.Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
The CVSS severity warrants an early asset and exposure review.Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.
The CVSS severity warrants an early asset and exposure review.Use of uninitialized resource in Windows RDP allows an unauthorized attacker to disclose information over a network.
The CVSS severity warrants an early asset and exposure review.