Impact
An open‑redirect flaw in Microsoft 365 Copilot allows an attacker to craft a malicious URL that, when presented in Copilot content or prompts, can redirect a user to an untrusted site. This redirect can be used to elevate privileges or compromise enterprise resources. The weakness corresponds to CWE‑601.
Affected Systems
The vulnerability affects all current releases of Microsoft 365 Copilot. No specific release numbers are listed, so all current releases should be treated as vulnerable until Microsoft issues a patch.
Risk and Exploitability
The CVSS score of 9.3 indicates a severe risk, while the EPSS score of less than 1 % suggests that exploitation is presently rare. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attacker would embed a malicious link within Copilot content or prompts; the victim must activate the link or otherwise trigger the redirect, after which the untrusted site can attempt to elevate privileges or compromise the network.
OpenCVE Enrichment