Impact
This vulnerability arises from improper neutralization of special elements used in a command, permitting command injection that can lead to information disclosure. An attacker can exploit the flaw to retrieve sensitive data transmitted over the network. The weakness is classified primarily as a command injection problem, potentially exposing data that should remain confidential.
Affected Systems
The affected system is Microsoft 365 Copilot’s Business Chat service. No specific version information is provided, so all active instances of Business Chat are potentially impacted until a patch is applied.
Risk and Exploitability
The CVSS score of 7.4 indicates a moderate to high severity, while the EPSS score of less than 1% suggests a low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is inferred to be over a network, as the description specifies disclosure over a network by an unauthorized attacker. No additional exploitation conditions are detailed in the provided information.
OpenCVE Enrichment