Impact
Deserialization of untrusted data in Microsoft 365 Copilot allows an authorized attacker to execute code over the network. This can lead to arbitrary code execution.
Affected Systems
Microsoft 365 Copilot. All installations of the product are potentially vulnerable until updated, as no version details are specified.
Risk and Exploitability
The CVSS score of 9.9 indicates critical severity and the EPSS score of 1% suggests a moderate probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attacker must possess authorized credentials and network connectivity to the Copilot service; without these, exploitation is unlikely. The flaw permits execution of arbitrary code over the network.
OpenCVE Enrichment