Impact
The flaw permits an attacker with legitimate Outlook Copilot access to inject special characters that are interpreted as part of a system command, leading to execution of arbitrary commands on the network. This does not grant code execution beyond the Copilot context, but allows the attacker to modify or delete data and disrupt business processes by manipulating network resources.
Affected Systems
Microsoft Copilot integrated into Microsoft Outlook is affected. The advisory does not list specific product or firmware revisions, so all currently supported Outlook Copilot deployments are considered vulnerable.
Risk and Exploitability
The CVSS score of 6.3 indicates a medium‑severity issue, while an EPSS score of less than 1% signals a low likelihood of exploitation at the time of analysis. The vulnerability is not included in the CISA KEV catalog. Exploitation requires authenticated use of Copilot; the attack vector is inferred to involve legitimate user activity that supplies malicious input through the Copilot interface to trigger command execution on the network.
OpenCVE Enrichment