Executive brief
Microsoft M365 Copilot, an AI-powered productivity tool integrated into Microsoft 365 apps, is vulnerable to a command injection flaw. An unauthorized attacker could exploit this over the network to tamper with data or system integrity. This could lead to unauthorized changes in documents, emails, or other corporate data managed by the AI assistant.
Technical details
A command injection vulnerability (CWE-77) exists in Microsoft M365 Copilot due to improper neutralization of special elements used in a command. The vulnerability can be exploited by an unauthenticated attacker over a network, though Microsoft's assessment suggests user interaction may be required (UI:R) and the impact is primarily on system integrity (tampering). Successful exploitation allows the attacker to execute unauthorized commands within the context of the Copilot environment. Affected components include Outlook for iOS versions prior to 5.2617.1. Microsoft has released security updates to address this issue.
Affected products
- Microsoft M365 Copilot Versions prior to May 2026 updates
- Microsoft Outlook for iOS versions up to (excluding) 5.2617.1
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory: Microsoft released the security update guide for this vulnerability.