Executive brief
A security vulnerability exists in Microsoft 365 Copilot, the AI-powered productivity tool integrated into Microsoft Office applications. An attacker with existing local access to a system could exploit this flaw to impersonate other users or services. This could lead to unauthorized actions being performed under a false identity, potentially compromising the integrity of internal communications or data.
Technical details
A vulnerability classified as improper access control (CWE-284) exists within Microsoft 365 Copilot. The flaw allows an attacker who is already authenticated to the local system to perform spoofing attacks. With a CVSS vector of AV:L/AC:L/PR:L/UI:N, the attack requires local access and low privileges but no user interaction. Successful exploitation allows the attacker to compromise the integrity and confidentiality of the application's operations by masquerading as a legitimate entity. Microsoft has released information regarding this vulnerability via the MSRC Update Guide.
Affected products
- Microsoft Copilot M365 Copilot
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory: Microsoft published the security advisory.