Vulnerabilità · 118 giorni fa

Le app Microsoft Android patchate possono ancora esporre l’accesso

Un bug dell’app corretto non mette automaticamente fine all’accesso che aveva già concesso. In queste app Microsoft 365 per Android, un’app malevola poteva ancora restare su un telefono come punto d’appoggio permanente dell’account perché i refresh token FOCI condivisi rimangono validi dopo l’update finché non vengono revocati.

CVE-2026-41101

NVD KEV

CVSS 7.1 HIGH: improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally. EPSS 0.3% (21º percentile). Patch Microsoft: Release Notes.

CVE-2026-41100

NVD KEV

CVSS 4.4 MEDIUM: improper access control in M365 Copilot allows an authorized attacker to perform spoofing locally. EPSS 0.3% (15º percentile). Patch Microsoft: Release Notes.

Cronologia

Fonti

2 fonti che coprono questa storia

Entità

Riepilogo fornitore: Microsoft

Part of the PlainSec briefing for 2026-06-03

Editions

Storie correlate