VDB

CVE-2024-38206

CVE-2024-38206 PUBLISHED CVSS 8.5 HIGH

An authenticated attacker can bypass Server-Side Request Forgery (SSRF) protection in Microsoft Copilot Studio to leak sensitive information over a network.

EPSS 12.34% · 95.8th percentile

Risk Scores

CVSS 3.1
8.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N/E:U/RL:O/RC:C
EPSS Score
12.34%
95.8th percentile

Affected Products

VendorProductVersions
MicrosoftMicrosoft Copilot StudioN/A, N/A
microsoftcopilot_studioN/A, N/A

Timeline

  • Aug 6, 2024 CVE Updated
  • Aug 6, 2024 CVE Published
  • Aug 7, 2024 PoC Published
  • Aug 13, 2024 EPSS Score
  • Aug 13, 2024 PoC Published
  • Aug 21, 2024 PoC Published
  • Aug 21, 2024 PoC Published
  • Aug 21, 2024 PoC Published
  • Aug 21, 2024 PoC Published
  • Aug 21, 2024 PoC Published
  • Aug 24, 2024 PoC Published
  • Sep 3, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›