CVE-2024-38206 is a medium-severity Server-Side Request Forgery (SSRF) bypass vulnerability in Microsoft Copilot Studio, allowing an authenticated attacker to leak sensitive information over a network. With a CVSS score of 6.5, this vulnerability requires low privileges and no user interaction, posing a high confidentiality impact. While not currently listed in CISA's KEV catalog, its EPSS score indicates a higher than average exploitability probability. There are no public exploits available (Metasploit, Nuclei, ExploitDB), but it has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:copilot_studio:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.