PT-2024-7988 · Microsoft · Copilot Studio

Mohammad Deilamy

·

Published

2024-08-14

·

Updated

2025-01-10

·

CVE-2024-43610

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Copilot Studio (affected versions not specified)
Description The issue is related to the exposure of sensitive information to unauthorized actors in Microsoft Copilot Studio. This allows an unauthenticated attacker to view sensitive information through a network attack vector. The vulnerability is associated with the disclosure of information and can be exploited by an attacker to gain unauthorized access to protected information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2024-09502
CVE-2024-43610

Affected Products

Copilot Studio