Impact
This vulnerability stems from improper neutralization of special elements used in a command within Microsoft Copilot Web, a weakness that can be exploited via command injection. An attacker who can supply crafted input may cause the application to expose sensitive information over the network, thereby breaching confidentiality. The flaw aligns with CWE‑77, indicating a classic command injection issue.
Affected Systems
Microsoft Copilot Web is the affected product. No specific version numbers are listed in the data, so all deployments of Copilot Web that have not yet applied a vendor‑supplied fix could be vulnerable.
Risk and Exploitability
The CVSS score of 8.8 classifies this flaw as high severity. The EPSS score of 1.63% indicates a low, but non‑zero exploitation probability, and it is not listed in CISA’s KEV catalog, so the potential impact remains significant. The likely attack vector is an attacker sending crafted input to the Copilot Web interface over a network, enabling unauthorized disclosure of information. The exploitation requires remote access to provide malicious input, but the high severity warrants prompt attention.
OpenCVE Enrichment