What Happened to Windows 365 Security Vulnerability?
Windows 365, Microsoft's Cloud PC service, has faced a continuous stream of security vulnerabilities since its launch, ranging from initial concerns over default administrator rights to sophisticated zero-day exploits and multi-factor authentication bypasses. Microsoft has consistently released patches and introduced new security features, including AI-driven defenses and enhanced endpoint management, to counter evolving threats, with significant updates and incident responses occurring as recently as August 2026.
Quick Answer
Windows 365 has been a consistent target for security vulnerabilities since its 2021 launch, including issues with default configurations, multi-factor authentication bypasses, and numerous zero-day exploits affecting both the Cloud PC environment and integrated Microsoft 365 services. Microsoft has actively responded with emergency patches, regular security updates, and the introduction of advanced security features like Windows Cloud IO Protection and AI-powered threat detection. As of August 2026, the focus remains on continuous patching, combating sophisticated phishing and AI-driven attacks, and enhancing built-in security and management capabilities across the Microsoft 365 ecosystem.
📊Key Facts
📅Complete Timeline15 events
Initial Security Concerns Raised on Windows 365 Launch
Upon its launch, security researchers on Infosec Twitter expressed concerns about Windows 365's default configuration, specifically granting local administrator rights to Cloud PC users, which was criticized for not being 'secure by default'.
Vulnerability Exposing Azure Credentials in Windows 365 Reported
A serious vulnerability affecting Windows 365 was reported, potentially allowing malicious individuals with administrative privileges to obtain Azure credentials of logged-in users.
CVE-2023-36884 (Windows HTML RCE) Actively Exploited
A critical zero-day vulnerability, CVE-2023-36884, affecting multiple Windows and Microsoft Office versions, was actively exploited, allowing remote code execution via specially crafted Office documents.
Microsoft 365 Copilot 'ASCII Smuggling' Vulnerability Patched
Microsoft patched a vulnerability in Microsoft 365 Copilot that allowed 'ASCII smuggling' and prompt injection to exfiltrate sensitive user information, including MFA codes.
Critical No-User-Interaction 2FA Bypass in Office 365 Disclosed
Security researchers revealed a critical vulnerability in Office 365's 2FA defenses that allowed bypass without user interaction, affecting 400 million users, which Microsoft subsequently remediated.
'EchoLeak' Zero-Click AI Vulnerability (CVE-2025-32711) in Copilot Found
A critical 'zero-click' AI vulnerability, CVE-2025-32711 (EchoLeak), was discovered in Microsoft 365 Copilot, allowing sensitive data exfiltration without user interaction by exploiting an LLM scope violation. Microsoft addressed the issue.
SharePoint Zero-Day Exploit (CVE-2025-53770) Actively Exploited
Hackers exploited a zero-day vulnerability in Microsoft SharePoint, impacting businesses and government agencies globally, prompting Microsoft to release emergency patches.
Windows Security Update Disrupts Cloud PC Access
A Windows security update (KB5074109) prevented some customers from accessing their Windows 365 Cloud PC sessions, causing authentication failures and service degradation.
Emergency Patch for Actively Exploited Office Zero-Day (CVE-2026-21509)
Microsoft rushed out an emergency patch for CVE-2026-21509, an actively exploited zero-day bug in Microsoft 365 and Office that allowed attackers to bypass security controls and execute arbitrary code.
Windows Cloud IO Protection Enters Public Preview
Microsoft announced Windows Cloud IO Protection, a new kernel-level driver and system-level encryption feature in public preview, designed to securely route keystrokes directly to Cloud PCs, bypassing OS layers vulnerable to malware.
FBI Warns of Kali365 MFA Bypass Kit
The FBI issued a formal warning about 'Kali365,' a phishing-as-a-service kit exploiting device code phishing to hijack Microsoft 365 accounts and bypass MFA without triggering new prompts.
Microsoft 365 Updates Include Enhanced Security Features
Microsoft began rolling out significant updates to Microsoft 365, Office 365, and EMS, including expanded protections through Microsoft Defender for Office 365 Plan 1 and advanced Intune capabilities.
Advanced Endpoint Management and AI Defenses Broadly Available
Microsoft announced that advanced endpoint management capabilities from the Intune Suite are now included in Microsoft 365 E5 and E3, alongside new AI-driven defenses like 'Project Perception' and prompt injection protection in Defender.
Midnight Blizzard 'CaptiveCrunch' Campaign Targets Microsoft 365 Accounts
Microsoft linked a global campaign by Russian threat actor Midnight Blizzard (APT29), dubbed 'CaptiveCrunch,' to targeting hospitality Wi-Fi networks to steal Microsoft 365 accounts via DNS manipulation and device code phishing.
Microsoft Teams Rolls Out Deepfake Meeting Reporting
Microsoft confirmed it is rolling out a new feature in Teams that allows users to report security issues, specifically targeting AI deepfake meetings, as part of ongoing efforts to combat evolving threats.
🔍Deep Dive Analysis
Since its introduction in 2021, Windows 365, often referred to as Cloud PC, has been under constant scrutiny regarding its security posture. Initial concerns arose shortly after its launch, with security researchers highlighting issues such as default local administrator rights for Cloud PC users, which was deemed not 'secure by default'. This raised questions about the foundational security configurations for enterprises adopting the virtual desktop service. Another early vulnerability in August 2021 could have allowed malicious actors with administrative privileges to gain Azure credentials from Windows 365 users.
Throughout 2023 and 2024, the landscape of threats expanded significantly. In September 2023, a critical zero-day vulnerability, CVE-2023-36884, affecting Microsoft Office and Windows HTML, allowed remote code execution via specially crafted Office documents, with active exploitation by threat groups like Storm-0978. Early 2024 saw a vulnerability in Microsoft 365 Copilot that enabled 'ASCII smuggling' to exfiltrate sensitive data, including multi-factor authentication (MFA) codes, through prompt injection. Later in 2024, a critical vulnerability allowing a no-user-interaction 2FA bypass in Office 365 was disclosed, putting over 400 million users at risk, though Microsoft quickly remediated it.
2025 brought further challenges, particularly with AI-driven components. In June 2025, the 'EchoLeak' flaw (CVE-2025-32711) in Microsoft 365 Copilot was discovered, a zero-click AI vulnerability that could exfiltrate sensitive data without user interaction by exploiting an 'LLM scope violation'. This year also saw a zero-day vulnerability in Microsoft SharePoint (CVE-2025-53770) being actively exploited, impacting government agencies and businesses globally. Additionally, remote code execution (CVE-2025-53733) and information disclosure (CVE-2025-59232) vulnerabilities were identified in Microsoft 365 Apps and Office Excel, respectively.
Into 2026, Microsoft has continued to face and address significant security incidents. January 2026 saw a Windows security update (KB5074109) disrupt access for some Windows 365 Cloud PC users, causing authentication failures. Simultaneously, an emergency patch was rushed out for CVE-2026-21509, an actively exploited zero-day bug in Microsoft 365 and Office that bypassed security controls and allowed arbitrary code execution. In May 2026, the FBI issued a warning about 'Kali365,' a phishing-as-a-service kit that exploited device code phishing to bypass Microsoft 365 MFA without password exposure or new MFA prompts, affecting hundreds of organizations. Most recently, as of July and August 2026, a global campaign dubbed 'CaptiveCrunch' by the Russian threat actor Midnight Blizzard (APT29) has been targeting hospitality Wi-Fi networks to hijack Microsoft 365 accounts through DNS manipulation and device code phishing. Microsoft has responded by rolling out significant security enhancements to Microsoft 365, including expanded Microsoft Defender for Office 365 Plan 1, advanced Intune capabilities, and the integration of Microsoft Security Copilot into E5 plans. New features like Windows Cloud IO Protection, in public preview since March 2026, aim to secure input for Windows 365 Cloud PCs against threats like keyloggers. Microsoft is also actively working on AI-driven defenses like 'Project Perception' and new prompt injection protection in Microsoft Defender. The company continues to emphasize regular updates and robust security practices to mitigate the ongoing and evolving threat landscape.
What If...?
Explore alternate histories. What if Windows 365 Security Vulnerability made different choices?