Executive brief
A security flaw has been identified in Microsoft 365 Copilot for Desktop, an AI-powered productivity tool. This vulnerability allows an unauthorized person with local access to the computer to spoof information or identities within the application. This could lead to the unauthorized viewing of sensitive information or the manipulation of the user's local environment.
Technical details
An improper access control vulnerability (CWE-284) exists in the Microsoft 365 Copilot for Desktop application. The flaw allows a local, unauthenticated attacker to bypass security restrictions to perform spoofing activities. According to the CVSS vector, while the primary impact is listed as high confidentiality loss, the vulnerability is exploited locally without requiring user interaction. This could allow an attacker to impersonate services or users within the Copilot interface to intercept sensitive data. Microsoft has released information regarding this vulnerability via the MSRC Update Guide.
Affected products
- Microsoft M365 Copilot for Desktop
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory