Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.
Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network.
Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network.
Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network.
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.
Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.
Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network.