Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.
Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose information over a network.
Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network.
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofing over a network.
The collection starts with 90 days of Microsoft updates and CISA additions, plus older Microsoft vulnerabilities still listed by CISA. Older entries do not imply that a product remains supported. Counts describe this collection, not every vulnerability or any customer environment.
Griffin Technology Partners managed customers may receive additional environment-specific security guidance and remediation assistance through their managed services relationship.
Security bulletins are provided for informational purposes and compiled from authoritative public sources. Vulnerability applicability varies by environment. Validate affected products, configuration, compatibility requirements, and vendor guidance before making production changes.