Impact
Improper authorization in Microsoft Copilot Cowork allows an unauthorized attacker to elevate privileges over a network, potentially gaining full control of the application and its underlying data. The vulnerability is a classic access control weakness (CWE-285) and can lead to unauthorized system access, data exposure, or manipulation by an attacker who originally had no privileges.
Affected Systems
Microsoft Copilot Cowork instances are affected; without version details, all deployments that have not applied the latest security updates may be vulnerable.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical severity. The EPSS score of 0.0039 confirms a very low but non-zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Likely attack vectors involve network access to the Copilot Cowork environment, and an attacker would need to exploit the flawed authorization checks to elevate privileges. Given the high score, the risk is significant, especially in unprotected or poorly segmented environments.
OpenCVE Enrichment