CVE-2026-41614
mediumCVSS v3 Base Score
6.2
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
Attack Characteristics
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Confidentiality
High
Integrity
None
Availability
None
Vulnerability Report
Generated by CyberWatcher
Description
Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally.
CWE
CWE-284Affected Products
Microsoft M365 Copilot for Desktop