Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unauthorized attacker to perform spoofing over a network.
The vulnerability stems from improper neutralization of input data during web page generation (CWE-79). An attacker can inject malicious script code that will be executed in the victim's browser context after interaction with prepared content. Due to the changed scope (S:C in the CVSS vector), the effects of script execution may extend beyond the source domain, enabling, among other things, impersonation of legitimate Microsoft Account content.
An attacker can gain access to sensitive user information (high confidentiality) and make unauthorized modifications to content or impersonate trusted resources (high integrity). The attack requires user interaction, such as clicking on a crafted link.
Apply patches available from the manufacturer in accordance with the references: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21264. As supplementary measures, it is recommended to exercise caution when clicking on links to Microsoft Account pages from untrusted sources.
Microsoft Account service — versions indicated in the manufacturer's references
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:NMicrosoft Account
APPMicrosoftall versions
Related vulnerabilities
Heap-based buffer overflow w Microsoft Account umożliwiający zdalne wykonanie kodu
Missing authorization in Microsoft Account allows an unauthorized attacker to elevate privileges over a networ...
Obejście uwierzytelnienia w Microsoft SharePoint Server (RCE-ready)
RCE przez deserializację niezaufanych danych w Microsoft SharePoint
Zdalne wykonanie kodu poprzez deserializację w Microsoft SharePoint Server