VDB
CVE-2024-49038
CVE-2024-49038
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorized attacker leads to elevation of privilege over a network.
EPSS 0.23% · 46.0th percentile
Risk Scores
CVSS v3.1
9.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C
EPSS Score
0.23%
46.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Microsoft Copilot Studio | N/A |
| microsoft | copilot_studio | N/A |
Timeline
- Nov 12, 2024 CVE Published
- Nov 26, 2024 PoC Published
- Nov 26, 2024 PoC Published
- Nov 27, 2024 EPSS Score
- Dec 15, 2024 EPSS Score
- Jan 1, 2025 EPSS Score
- Jan 19, 2025 EPSS Score
- Jan 20, 2025 Coalition ESS Score
- Feb 5, 2025 EPSS Score
- Feb 22, 2025 EPSS Score
- Mar 11, 2025 EPSS Score
- Mar 28, 2025 EPSS Score