Microsoft Data Formulator Remote Code Execution Vulnerability
Vulnerability
A code injection vulnerability has been identified in Microsoft Data Formulator, allowing unauthorized attackers to execute code remotely over a network. This issue arises from improper control of code generation, which could be exploited by manipulating user-supplied input that is processed by the affected application.
Impact
Exploitation of this vulnerability allows for remote code execution on the affected system.
Remediation
Users can download the security update for Microsoft Data Formulator from the Python Package Index (PyPI).
Added: May 12, 2026, 7:23 PM
Updated: May 12, 2026, 7:23 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
7.5exploitability
6.4remediation
0.0relevance
8.2threat
0.0urgency
2.9incentive
0.0Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
