Executive brief
Microsoft Data Formulator, a tool used for data preparation and transformation, is vulnerable to a code injection flaw. An unauthorized attacker can exploit this vulnerability over a network to execute arbitrary commands on the affected system. This could lead to a complete compromise of the application, unauthorized access to sensitive data, and disruption of business operations.
Technical details
A code injection vulnerability (CWE-94) exists in Microsoft Data Formulator due to improper control of code generation. The flaw allows an unauthenticated attacker to execute arbitrary code over the network, provided there is some level of user interaction (as indicated by the UI:R CVSS metric). The vulnerability has a CVSS 3.1 base score of 8.8, reflecting high impact on confidentiality, integrity, and availability. Security updates are typically available through the Microsoft Security Response Center (MSRC) update guide.
Affected products
- Microsoft Data Formulator
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory