Impact
The vulnerability is a server‑side request forgery that permits an authorized attacker to instruct Microsoft Copilot in Azure to retrieve internal network resources, potentially exposing sensitive data. This weakness follows CWE‑918 and results in unauthorized disclosure of information accessible to the service.
Affected Systems
Microsoft Copilot in Azure, all deployed instances—specific vulnerable versions are not enumerated in the advisories. Any environment running the service is potentially affected.
Risk and Exploitability
The CVSS score of 7.7 denotes high severity, yet the EPSS score is currently unavailable and the vulnerability has not been listed in CISA's KEV catalog. The attack vector is a server‑side request forgery accessible by an authenticated user; once exploited, the attacker can force the service to contact internal endpoints, leading to data disclosure or facilitating further lateral movement. The risk remains significant for organizations that have not applied any vendor‑issued fix.
OpenCVE Enrichment