CVE-2026-41101
CVSS 7.1 HIGH: improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally. EPSS 0.3% (21º percentile). Patch Microsoft: Release Notes.
Vulnerabilità · 118 giorni fa
Un bug dell’app corretto non mette automaticamente fine all’accesso che aveva già concesso. In queste app Microsoft 365 per Android, un’app malevola poteva ancora restare su un telefono come punto d’appoggio permanente dell’account perché i refresh token FOCI condivisi rimangono validi dopo l’update finché non vengono revocati.
CVSS 7.1 HIGH: improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally. EPSS 0.3% (21º percentile). Patch Microsoft: Release Notes.
CVSS 4.4 MEDIUM: improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally. EPSS 0.3% (15º percentile). Patch Microsoft: Release Notes.
2 fonti che coprono questa storia
Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag
Debug flag disabled Microsoft 365 Android token checks, letting untrusted apps access accounts; patches issued May 12 to reduce risk
Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk
A simple development setting bypassed protections designed to prevent unauthorized Android apps from accessing Microsoft account tokens, exposing billions of installations.
Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-06-03