Microsoft Power Automate
cpe:2.3:a:microsoft:power_automate_for_desktop:*:*:*:*:*:*:*
A vulnerability exists in Power Automate for Desktop due to an uncontrolled search path element. This flaw allows an authorized attacker to disclose information over a network, potentially including NTLM hashes.
Exploitation of this vulnerability could lead to unauthorized information disclosure, specifically NTLM hash values.
Users can apply the official security update available through the Microsoft Store to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.