News

Microsoft Copilot Studio Vulnerability

Microsoft Copilot Studio Vulnerability

Citizen

Citizen Sec , 09-09-2024

News
#Critical vulnerability
#Information Security
Microsoft Copilot Studio Vulnerability

Recently, it was revealed that a serious vulnerability was discovered in Microsoft Copilot Studio, which could threaten the internal security of the company. This vulnerability, known as SSRF (server-side request forgery), could allow attackers to gain access to confidential data. Researchers from Tenable noticed that Copilot Studio has a feature that allows users to send HTTP requests.


They decided to test this feature and found that with minor modifications to the requests, they were able to bypass the SSRF protection. This allowed them to redirect requests to their own server and access internal data. Although the initially obtained information was not confidential, the researchers were able to extract access tokens, highlighting the seriousness of the issue.


Ultimately, they gained access to Azure subscriptions and were able to discover a Cosmos DB instance that they could access through Copilot. This vulnerability, designated CVE-2024-38206, was rated as critical with a score of 8.5 on the CVSS scale. After discovering the vulnerability, Tenable reported it to Microsoft, which quickly fixed the issue and confirmed that users do not need to take any action to receive the patch.


It is important to stay updated and use the latest versions of software to protect your data from such threats.


You will be interested

News
#Critical vulnerability

Новый вирус для Android — ERMAC 3.0

В сети появился новый вредоносный вирус для телефонов на Android под названием ERMAC 3.0. Его главная цель — кража личных данных и денежных средств пользователей.

Citizen Sec

18-08-2025
News
#Information Security
#Critical vulnerability

Zebo-0.1.0 and Cometlogger-0.1: Dangerous Programs Stealing Data and Controlling Computers

Experts have discovered two dangerous programs that seem harmless at first. These programs can steal personal data, monitor computer activity, and even take control of the system.

Citizen Sec

26-12-2024
News
#Critical vulnerability
#Information Security

Critical vulnerability CVE-2024-43093 threatens the security of Android users

This problem allows hackers to gain unauthorized access to important Android system folders.

Citizen Sec

05-11-2024
News
#Information Security
#Critical vulnerability

Unpatched vulnerability in AVTECH cameras: hackers are taking over devices to create botnets.

Serious vulnerabilities have been discovered in AVTECH surveillance cameras, which malicious actors use to infect devices with malware.

Citizen Sec

05-09-2024
News
#Information Security
#Critical vulnerability

The vulnerability of the LiteSpeed Cache plugin threatens over 5 million WordPress sites

Recently, security researcher John Blackburn from PatchStack discovered a serious vulnerability in the LiteSpeed Cache plugin, which is used to speed up WordPress sites.

Citizen Sec

28-08-2024
News
#Information Security
#Critical vulnerability

Google warns: vulnerability CVE-2024-7965 in Chrome is under active exploitation

Google has reported a security issue in its Chrome browser that has been fixed in the latest update.

Citizen Sec

27-08-2024
News
#Information Security
#Critical vulnerability

Critical Vulnerability in OpenSSH on FreeBSD

A serious security vulnerability was recently discovered in OpenSSH on FreeBSD systems.

Citizen Sec

14-08-2024
News
#Information Security
#Critical vulnerability

Vulnerability in MongoDB Allows Attackers to Gain Full Control of Windows Systems

A critical vulnerability has been discovered in MongoDB, identified as CVE-2024-7553.

Citizen Sec

12-08-2024
News
#Information Security
#Critical vulnerability

Анализ вредоносного кода в бэкдоре XZ Utils - как хакеры эксплуатируют популярный архиватор для атак

В конце марта в популярной библиотеке XZ Utils был обнаружен бэкдор, который получил идентификатор CVE-2024-3094.

Citizen Sec

16-07-2024