QID 92091
QID 92091: Microsoft Power Platform Connector Spoofing Vulnerability for December 2023
A Power Platform connector is a proxy or a wrapper around an API that allows the underlying service to talk to Microsoft Power Automate, Microsoft Power Apps, and Azure Logic Apps.
Successful exploitation allows an unauthenticated, remote attacker to manipulate a malicious link, application, or file to disguise it as a legitimate link or file to trick the victim.
Solution
Customers are advised to refer to CVE-2023-36019 for more details pertaining to this vulnerability.
Vendor References
- CVE-2023-36019 -
msrc.microsoft.com/update-guide/en-US/advisory/CVE-2023-36019
CVEs related to QID 92091
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2023-36019 |
|