Vulnerabilità ed exploit · Furto di credenziali

Le app Microsoft Android patchate possono ancora esporre l’accesso

Un bug dell’app corretto non mette automaticamente fine all’accesso che aveva già concesso. In queste app Microsoft 365 per Android, un’app malevola poteva ancora restare su un telefono come punto d’appoggio permanente dell’account perché i refresh token FOCI condivisi rimangono validi dopo l’update finché non vengono revocati.

2 fonti · 3 giu

CVE-2026-41101

NVD KEV

CVSS 7.1 HIGH: improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally. EPSS 0.3% (21º percentile). Patch Microsoft: Release Notes.

CVE-2026-41100

NVD KEV

CVSS 4.4 MEDIUM: improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally. EPSS 0.3% (15º percentile). Patch Microsoft: Release Notes.

Cronologia

Fonti

Riepilogo fornitore: Microsoft

Part of the PlainSec briefing for 2026-06-03

Every edition of this story: Le app Microsoft Android patchate possono ancora esporre l’accesso

Altro da oggi