OSINTxLab
OSINT://LAB INTEL NODE ONLINE 2026.08.04 08:18 CST
文章详情

正文阅读

分类:威胁情报

2026-06-15 1 分钟 60 阅读

Alleged Vulnerability in Microsoft 365 Copilot Enterprise

OSINTxLab 60 阅读 · 1 分钟
事件类型
Vulnerability
报告时间
2026-06-15 22:05:22
被攻击国家/地区
USA
被攻击行业
Information Technology (IT) Services
被攻击组织
microsoft
被攻击域名
microsoft.com
攻击组织
None
信息来源
openweb
Original Text
原文内容
查看原文

A critical vulnerability chain dubbed SearchLeak (CVE-2026-42824) was discovered in Microsoft 365 Copilot Enterprise, enabling potential one-click data theft via a malicious URL. The attack chained three flaws-prompt injection through the Copilot search parameter, an HTML rendering race condition, and an SSRF issue in Bing’s image search to extract sensitive data from emails, OneDrive, SharePoint, and calendar events. When a victim clicks a crafted link, Copilot is manipulated into retrieving internal data and embedding it in image requests that are silently sent to an attacker-controlled server via Bing. Microsoft has already patched the issue, and no user action is required, but it highlights how combining multiple vulnerabilities can turn AI systems into powerful data exfiltration tools.