Multiple critical vulnerabilities in Microsoft 365 Copilot (CVSS Base Score 9.8) allow a remote, anonymous attacker to elevate privileges, perform command injection, manipulate data, or disclose sensitive information. The advisory, dated June 21, 2026, indicates that mitigations are available, but the article does not specify the affected version ranges, the exact fixed versions, or specific workarounds.
[WID-SEC-2026-2020] Microsoft 365 Copilot: Mehrere Schwachstellen CVSS Base Score 9.8 (kritisch) CVSS Temporal Score 8.5 (hoch) Remoteangriff ja Datum 21.06.2026 Stand 22.06.2026 Mitigation ja Betroffene Systeme Betriebssystem Windows Produktbeschreibung Microsoft Copilot ist ein KI-Assistent, der in verschiedene Microsoft-Produkte integriert werden kann. Produkte 21.06.2026 Microsoft 365 Copilot Angriff Angriff Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Microsoft 365 Copilot ausnutzen, um seine Privilegien zu erhöhen, Befehlsinjektionen durchzufĂŒhren, Daten zu manipulieren oder vertrauliche Informationen offenzulegen. CVE Informationen Versionshistorie Feedback zum Advisory geben