{
  "document" : {
    "aggregate_severity" : {
      "text" : "hoch"
    },
    "category" : "csaf_base",
    "csaf_version" : "2.0",
    "distribution" : {
      "tlp" : {
        "label" : "WHITE",
        "url" : "https://www.first.org/tlp/"
      }
    },
    "lang" : "de-DE",
    "notes" : [ {
      "category" : "legal_disclaimer",
      "text" : "Das BSI ist als Anbieter für die eigenen, zur Nutzung bereitgestellten Inhalte nach den allgemeinen Gesetzen verantwortlich. Nutzerinnen und Nutzer sind jedoch dafür verantwortlich, die Verwendung und/oder die Umsetzung der mit den Inhalten bereitgestellten Informationen sorgfältig im Einzelfall zu prüfen."
    }, {
      "category" : "description",
      "text" : "Azure ist eine Cloud Computing-Plattform von Microsoft.\r\nMicrosoft Copilot ist ein KI-Assistent, der in verschiedene Microsoft-Produkte integriert werden kann.\r\nExchange ist ein Groupware und Nachrichtensystem der Firma Microsoft.\r\nMicrosoft bietet in der Apps-Produktfamilie zahlreiche Anwendungen  für mobile Endgeräte an.",
      "title" : "Produktbeschreibung"
    }, {
      "category" : "summary",
      "text" : "Ein Angreifer kann mehrere Schwachstellen in Microsoft Azure, Microsoft 365 Copilot, Microsoft Exchange und Microsoft Apps Surface ausnutzen, um seine Privilegien zu erhöhen, beliebigen Code auszuführen, Daten zu manipulieren oder vertrauliche Informationen offenzulegen.",
      "title" : "Angriff"
    }, {
      "category" : "general",
      "text" : "- Windows",
      "title" : "Betroffene Betriebssysteme"
    } ],
    "publisher" : {
      "category" : "other",
      "contact_details" : "csaf-provider@cert-bund.de",
      "name" : "Bundesamt für Sicherheit in der Informationstechnik",
      "namespace" : "https://www.bsi.bund.de"
    },
    "references" : [ {
      "category" : "self",
      "summary" : "WID-SEC-W-2026-2502 - CSAF Version",
      "url" : "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2502.json"
    }, {
      "category" : "self",
      "summary" : "WID-SEC-2026-2502 - Portal Version",
      "url" : "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2502"
    }, {
      "category" : "external",
      "summary" : "Microsoft Security Advisory CVE-2026-35425 vom 2026-07-23",
      "url" : "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35425"
    }, {
      "category" : "external",
      "summary" : "Microsoft Security Advisory CVE-2026-49159 vom 2026-07-23",
      "url" : "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49159"
    }, {
      "category" : "external",
      "summary" : "Microsoft Security Advisory CVE-2026-56160 vom 2026-07-23",
      "url" : "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56160"
    }, {
      "category" : "external",
      "summary" : "Microsoft Security Advisory CVE-2026-56163 vom 2026-07-23",
      "url" : "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56163"
    }, {
      "category" : "external",
      "summary" : "Microsoft Security Advisory CVE-2026-56165 vom 2026-07-23",
      "url" : "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56165"
    }, {
      "category" : "external",
      "summary" : "Microsoft Security Advisory CVE-2026-56167 vom 2026-07-23",
      "url" : "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56167"
    }, {
      "category" : "external",
      "summary" : "Microsoft Security Advisory CVE-2026-57106 vom 2026-07-23",
      "url" : "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57106"
    }, {
      "category" : "external",
      "summary" : "Microsoft Security Advisory CVE-2026-58275 vom 2026-07-23",
      "url" : "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58275"
    }, {
      "category" : "external",
      "summary" : "Microsoft Security Advisory CVE-2026-58630 vom 2026-07-23",
      "url" : "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58630"
    }, {
      "category" : "external",
      "summary" : "Microsoft Security Advisory CVE-2026-62825 vom 2026-07-23",
      "url" : "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62825"
    }, {
      "category" : "external",
      "summary" : "Microsoft Security Advisory CVE-2026-50517 vom 2026-07-23",
      "url" : "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50517"
    }, {
      "category" : "external",
      "summary" : "Microsoft Security Advisory CVE-2026-56191 vom 2026-07-23",
      "url" : "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56191"
    }, {
      "category" : "external",
      "summary" : "Microsoft Security Advisory CVE-2026-54120 vom 2026-07-23",
      "url" : "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54120"
    }, {
      "category" : "external",
      "summary" : "Microsoft Leitfaden für Sicherheitsupdates vom 2026-07-23",
      "url" : "https://msrc.microsoft.com/update-guide/"
    } ],
    "source_lang" : "en-US",
    "title" : "Microsoft Azure, Copilot, Exchange, Surface: Mehrere Schwachstellen",
    "tracking" : {
      "current_release_date" : "2026-07-26T22:00:00.000+00:00",
      "generator" : {
        "date" : "2026-07-27T08:43:03.900+00:00",
        "engine" : {
          "name" : "BSI-WID",
          "version" : "1.6.0"
        }
      },
      "id" : "WID-SEC-W-2026-2502",
      "initial_release_date" : "2026-07-23T22:00:00.000+00:00",
      "revision_history" : [ {
        "date" : "2026-07-23T22:00:00.000+00:00",
        "number" : "1",
        "summary" : "Initiale Fassung"
      }, {
        "date" : "2026-07-26T22:00:00.000+00:00",
        "number" : "2",
        "summary" : "Referenz(en) aufgenommen: EUVD-2026-48603, EUVD-2026-48602, EUVD-2026-48601"
      } ],
      "status" : "final",
      "version" : "2"
    }
  },
  "product_tree" : {
    "branches" : [ {
      "branches" : [ {
        "category" : "product_name",
        "name" : "Microsoft 365 Copilot",
        "product" : {
          "name" : "Microsoft 365 Copilot",
          "product_id" : "T057171",
          "product_identification_helper" : {
            "cpe" : "cpe:/a:microsoft:365_copilot:-"
          }
        }
      }, {
        "branches" : [ {
          "category" : "product_version",
          "name" : "Surface Management Services",
          "product" : {
            "name" : "Microsoft Apps Surface Management Services",
            "product_id" : "T057174",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:microsoft:apps:surface_management_services"
            }
          }
        } ],
        "category" : "product_name",
        "name" : "Apps"
      }, {
        "branches" : [ {
          "category" : "product_version",
          "name" : "API Management (APIM)",
          "product" : {
            "name" : "Microsoft Azure API Management (APIM)",
            "product_id" : "T057161",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:microsoft:azure:api_management_%28apim%29"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "Red Hat OpenShift (ARO)",
          "product" : {
            "name" : "Microsoft Azure Red Hat OpenShift (ARO)",
            "product_id" : "T057162",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:microsoft:azure:red_hat_openshift_%28aro%29"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "Kubernetes Service",
          "product" : {
            "name" : "Microsoft Azure Kubernetes Service",
            "product_id" : "T057163",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:microsoft:azure:kubernetes_service"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "Microsoft Graph",
          "product" : {
            "name" : "Microsoft Azure Microsoft Graph",
            "product_id" : "T057164",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:microsoft:azure:microsoft_graph"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "Microsoft Account",
          "product" : {
            "name" : "Microsoft Azure Microsoft Account",
            "product_id" : "T057165",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:microsoft:azure:microsoft_account"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "AI Search",
          "product" : {
            "name" : "Microsoft Azure AI Search",
            "product_id" : "T057166",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:microsoft:azure:ai_search"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "DNS",
          "product" : {
            "name" : "Microsoft Azure DNS",
            "product_id" : "T057167",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:microsoft:azure:dns"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "App Service for Linux",
          "product" : {
            "name" : "Microsoft Azure App Service for Linux",
            "product_id" : "T057168",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:microsoft:azure:app_service_for_linux"
            }
          }
        }, {
          "category" : "product_version",
          "name" : "Key Vault",
          "product" : {
            "name" : "Microsoft Azure Key Vault",
            "product_id" : "T057169",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:microsoft:azure:key_vault"
            }
          }
        } ],
        "category" : "product_name",
        "name" : "Azure"
      }, {
        "branches" : [ {
          "category" : "product_version",
          "name" : "Online",
          "product" : {
            "name" : "Microsoft Exchange Online",
            "product_id" : "T057172",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:microsoft:exchange:online"
            }
          }
        } ],
        "category" : "product_name",
        "name" : "Exchange"
      } ],
      "category" : "vendor",
      "name" : "Microsoft"
    } ]
  },
  "vulnerabilities" : [ {
    "cve" : "CVE-2026-35425",
    "product_status" : {
      "known_affected" : [ "T057161", "T057162", "T057163", "T057164", "T057165", "T057166", "T057167", "T057168", "T057169" ]
    },
    "release_date" : "2026-07-23T22:00:00.000+00:00",
    "title" : "CVE-2026-35425"
  }, {
    "cve" : "CVE-2026-49159",
    "product_status" : {
      "known_affected" : [ "T057161", "T057162", "T057163", "T057164", "T057165", "T057166", "T057167", "T057168", "T057169" ]
    },
    "release_date" : "2026-07-23T22:00:00.000+00:00",
    "title" : "CVE-2026-49159"
  }, {
    "cve" : "CVE-2026-56160",
    "product_status" : {
      "known_affected" : [ "T057161", "T057162", "T057163", "T057164", "T057165", "T057166", "T057167", "T057168", "T057169" ]
    },
    "release_date" : "2026-07-23T22:00:00.000+00:00",
    "title" : "CVE-2026-56160"
  }, {
    "cve" : "CVE-2026-56163",
    "product_status" : {
      "known_affected" : [ "T057161", "T057162", "T057163", "T057164", "T057165", "T057166", "T057167", "T057168", "T057169" ]
    },
    "release_date" : "2026-07-23T22:00:00.000+00:00",
    "title" : "CVE-2026-56163"
  }, {
    "cve" : "CVE-2026-56165",
    "product_status" : {
      "known_affected" : [ "T057161", "T057162", "T057163", "T057164", "T057165", "T057166", "T057167", "T057168", "T057169" ]
    },
    "release_date" : "2026-07-23T22:00:00.000+00:00",
    "title" : "CVE-2026-56165"
  }, {
    "cve" : "CVE-2026-56167",
    "product_status" : {
      "known_affected" : [ "T057161", "T057162", "T057163", "T057164", "T057165", "T057166", "T057167", "T057168", "T057169" ]
    },
    "release_date" : "2026-07-23T22:00:00.000+00:00",
    "title" : "CVE-2026-56167"
  }, {
    "cve" : "CVE-2026-57106",
    "product_status" : {
      "known_affected" : [ "T057161", "T057162", "T057163", "T057164", "T057165", "T057166", "T057167", "T057168", "T057169" ]
    },
    "release_date" : "2026-07-23T22:00:00.000+00:00",
    "title" : "CVE-2026-57106"
  }, {
    "cve" : "CVE-2026-58275",
    "product_status" : {
      "known_affected" : [ "T057161", "T057162", "T057163", "T057164", "T057165", "T057166", "T057167", "T057168", "T057169" ]
    },
    "release_date" : "2026-07-23T22:00:00.000+00:00",
    "title" : "CVE-2026-58275"
  }, {
    "cve" : "CVE-2026-58630",
    "product_status" : {
      "known_affected" : [ "T057161", "T057162", "T057163", "T057164", "T057165", "T057166", "T057167", "T057168", "T057169" ]
    },
    "release_date" : "2026-07-23T22:00:00.000+00:00",
    "title" : "CVE-2026-58630"
  }, {
    "cve" : "CVE-2026-62825",
    "product_status" : {
      "known_affected" : [ "T057161", "T057162", "T057163", "T057164", "T057165", "T057166", "T057167", "T057168", "T057169" ]
    },
    "release_date" : "2026-07-23T22:00:00.000+00:00",
    "title" : "CVE-2026-62825"
  }, {
    "cve" : "CVE-2026-50517",
    "product_status" : {
      "known_affected" : [ "T057171" ]
    },
    "release_date" : "2026-07-23T22:00:00.000+00:00",
    "title" : "CVE-2026-50517"
  }, {
    "cve" : "CVE-2026-56191",
    "product_status" : {
      "known_affected" : [ "T057172" ]
    },
    "release_date" : "2026-07-23T22:00:00.000+00:00",
    "title" : "CVE-2026-56191"
  }, {
    "cve" : "CVE-2026-54120",
    "product_status" : {
      "known_affected" : [ "T057174" ]
    },
    "release_date" : "2026-07-23T22:00:00.000+00:00",
    "title" : "CVE-2026-54120"
  } ]
}