Impact
The vulnerability is an incorrect assignment of permissions to a critical resource in Microsoft 365 Copilot, which enables an authorized attacker to disclose sensitive information over the network. Based on the description, it is inferred that the flaw does not involve code execution or denial of service; it simply allows the exploitation of an existing access privilege to read confidential data that should be protected. The weakness is tied to incorrect permission handling (CWE‑732).
Affected Systems
Microsoft 365 Copilot is affected. No specific version or build details are provided, so any deployed instance of Copilot may be vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity, but the EPSS score of less than 1% suggests a low likelihood that exploitation is already occurring in the wild. The vulnerability is not listed in CISA’s KEV catalog, implying no known widespread exploitation. Based on the description, the likely attack vector is an authenticated attacker who already has legitimate access to the Copilot environment; there is no remote exploitation vector. Consequently, the risk is primarily to internal users who possess valid credentials, and the compromise would result in unwanted disclosure of confidential corporate data.
OpenCVE Enrichment