Impact
The vulnerability is a command injection weakness (CWE-77) in Microsoft 365 Copilot, allowing an authorized attacker to craft special elements that bypass safe command handling and elevate their privileges over a network. This can lead to unauthorized control of network resources and compromise data integrity and confidentiality.
Affected Systems
Microsoft 365 Copilot. The vulnerability affects all installations of the product for which Microsoft has not released a fix that addresses this specific command injection flaw.
Risk and Exploitability
The CVSS score of 9.9 indicates critical severity, while the EPSS score of less than 1% suggests the probability of exploitation is currently very low. The vulnerability is not listed in the CISA KEV catalog, indicating no known active exploitation. The attack requires an authorized user to supply malicious input; it is not remotely exploitable from the Internet but can be leveraged by insiders or compromised accounts to raise privileges across the organization.
OpenCVE Enrichment