Impact
The vulnerability in Microsoft 365 Copilot’s Business Chat, identified as CWE‑138, arises from an improper neutralization of special elements used in a command. When an attacker can influence the Chat input to include such elements, the system incorrectly processes them, allowing the attacker to read sensitive data that is normally protected. The primary effect is the accidental disclosure of private information to an unauthorized party.
Affected Systems
All instances of Microsoft 365 Copilot’s Business Chat are potentially impacted, as no specific version constraints are listed by the vendor. Users who enable or regularly use the Business Chat feature are at risk.
Risk and Exploitability
With a CVSS score of 7.5 the flaw is classified as high severity for information disclosure. The EPSS score of 1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need to inject or manipulate chat content, a capability that is limited to accounts with access to the Business Chat interface or to public-facing chat surfaces that accept user input.
OpenCVE Enrichment