Impact
The vulnerability arises from improper neutralization of special elements used in a command, allowing command injection in Microsoft Copilot. This flaw lets an unauthorized attacker issue crafted instructions that the Copilot backend executes, leading to disclosure of sensitive data or system state over the network. The impact is a loss of confidentiality for any information that the affected service handles.
Affected Systems
Microsoft Copilot deployments are impacted. All current versions of the Copilot service that have not received the Microsoft patch are vulnerable. Specific version numbers are not listed, so any supported release should be treated as at risk until an official update is applied.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity, while the EPSS score of less than 1 % shows a low probability of exploitation at the time of analysis. Because the flaw is not yet listed in CISA KEV, it has not been widely exploited, yet the attack appears to require an attacker to send a crafted command to the Copilot service over a network, implying a remote attack vector. The combination of moderate severity and low exploitation likelihood suggests a moderate risk that warrants prompt mitigation to avoid potential data leakage.
OpenCVE Enrichment