Executive brief
Microsoft Copilot, an AI-powered productivity tool, is affected by a security flaw that could allow an unauthorized person to tamper with data over the internet. An attacker could potentially manipulate the commands or outputs of the AI assistant, though this requires some level of user interaction. This could lead to unauthorized changes in information or the integrity of the service's operations.
Technical details
A command injection vulnerability (CWE-77) exists in Microsoft Copilot due to improper neutralization of special elements used in commands. The vulnerability is exploitable over the network without authentication, though the CVSS vector indicates that user interaction is required (UI:R). An attacker can leverage this flaw to perform unauthorized tampering with the service. The vulnerability is classified as affecting an exclusively hosted service, suggesting the fix is managed by the provider.
Affected products
- Microsoft Microsoft 365 Copilot unspecified
Timeline
- 2026-06-19: disclosed
- 2026-06-19: advisory