VDB
CVE-2024-43610
CVE-2024-43610
PUBLISHED
CVSS 7.400000095367432 HIGH
Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through network attack vector
EPSS 1.00% · 60.3th percentile
Risk Scores
CVSS 3.1
7.400000095367432
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C
EPSS Score
1.00%
60.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| microsoft | copilot_studio | N/A, - |
| Microsoft | Microsoft Copilot Studio | N/A, - |
| Microsoft | N/A |
Timeline
- Oct 8, 2024 CVE Published
- Oct 9, 2024 PoC Published
- Oct 10, 2024 EPSS Score
- Oct 14, 2024 Coalition ESS Score
- Oct 29, 2024 EPSS Score
- Dec 7, 2024 EPSS Score
- Dec 26, 2024 EPSS Score
- Jan 10, 2025 CVE Updated
- Jan 14, 2025 EPSS Score
- Jan 20, 2025 Coalition ESS Score
- Jan 23, 2025 PoC Published
- Feb 21, 2025 EPSS Score