Microsoft Patches 18 Vulnerabilities in AI, Cloud Products
Microsoft released patches for 18 vulnerabilities on Thursday, spanning its Azure cloud portfolio and Copilot-branded AI products.
Elevation of privilege flaws made up the bulk of the disclosures, affecting Azure ARC, Azure AI Foundry, Azure Logic Apps, Azure Billing, Azure HorizonDB, Azure Cosmos DB, Azure Container Registry, Microsoft Fabric, Microsoft Dataverse, and Microsoft 365 Copilot.
Several information disclosure vulnerabilities were addressed in Copilot, Microsoft 365 Copilot, Microsoft 365 Copilot Business Chat, and Azure Machine Learning. A single spoofing vulnerability was patched in Azure Portal.
Microsoft rated all vulnerabilities as critical, but their CVSS scores indicate high or medium severity for some.
While some of these flaws were discovered internally by Microsoft, many were reported to the software giant by external researchers.
None of the vulnerabilities have been flagged as exploited, and Microsoft noted that all fixes were implemented on the server side, meaning that customers do not need to take...
Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE