Impact
Microsoft Copilot Studio contains a flaw where it fails to properly verify the cryptographic signature of certain operations. This weakness allows an attacker who can deliver a forged packet over the network to gain elevated privileges within the application, potentially enabling execution of arbitrary code or modification of data. The vulnerability is classified as CWE-347, reflecting an improper verification of a critical cryptographic value.
Affected Systems
The issue affects all deployments of Microsoft Copilot Studio. No specific version range is listed by Microsoft, so any installed instance is potentially vulnerable until a patch is applied.
Risk and Exploitability
The CVSS base score of 9.3 indicates a severe exploitation risk. No EPSS score is available, so the current probability of exploitation is unknown, but the lack of a KEV listing means the vulnerability has not yet been observed in the wild. Based on the nature of the flaw, the likely attack vector is a network‑based delivery of a forged payload that bypasses signature checks. Once the signature is accepted, the attacker can execute privileged actions within the Copilot Studio environment.
OpenCVE Enrichment