VDB
CVE-2024-38206
CVE-2024-38206
PUBLISHED
CVSS 8.5 HIGH
An authenticated attacker can bypass Server-Side Request Forgery (SSRF) protection in Microsoft Copilot Studio to leak sensitive information over a network.
EPSS 12.34% · 95.8th percentile
Risk Scores
CVSS 3.1
8.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N/E:U/RL:O/RC:C
EPSS Score
12.34%
95.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Microsoft Copilot Studio | N/A, N/A |
| microsoft | copilot_studio | N/A, N/A |
Timeline
- Aug 6, 2024 CVE Updated
- Aug 6, 2024 CVE Published
- Aug 7, 2024 PoC Published
- Aug 13, 2024 EPSS Score
- Aug 13, 2024 PoC Published
- Aug 21, 2024 PoC Published
- Aug 21, 2024 PoC Published
- Aug 21, 2024 PoC Published
- Aug 21, 2024 PoC Published
- Aug 21, 2024 PoC Published
- Aug 24, 2024 PoC Published
- Sep 3, 2024 EPSS Score