VDB

CVE-2024-43610

CVE-2024-43610 PUBLISHED CVSS 7.400000095367432 HIGH

Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through network attack vector

EPSS 1.00% · 60.3th percentile

Risk Scores

CVSS 3.1
7.400000095367432
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C
EPSS Score
1.00%
60.3th percentile

Affected Products

VendorProductVersions
microsoftcopilot_studioN/A, -
MicrosoftMicrosoft Copilot StudioN/A, -
MicrosoftN/A

Timeline

  • Oct 8, 2024 CVE Published
  • Oct 9, 2024 PoC Published
  • Oct 10, 2024 EPSS Score
  • Oct 14, 2024 Coalition ESS Score
  • Oct 29, 2024 EPSS Score
  • Dec 7, 2024 EPSS Score
  • Dec 26, 2024 EPSS Score
  • Jan 10, 2025 CVE Updated
  • Jan 14, 2025 EPSS Score
  • Jan 20, 2025 Coalition ESS Score
  • Jan 23, 2025 PoC Published
  • Feb 21, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›