Executive brief
Microsoft Outlook Copilot, an AI-powered assistant for email and scheduling, contains a security vulnerability that could allow an authorized user to manipulate system commands. An attacker with basic access could potentially tamper with data or gain unauthorized access to sensitive information. While the attack requires some user interaction, it poses a risk to the integrity of communications and corporate data handled by the AI assistant.
Technical details
A command injection vulnerability (CWE-77) exists in Microsoft Copilot for Outlook due to improper neutralization of special elements used in commands. An attacker with low-level privileges (PR:L) can exploit this over the network by inducing a user to perform a specific action (UI:R). Successful exploitation allows the attacker to perform unauthorized tampering and potentially achieve high confidentiality impact by accessing sensitive data processed by the AI assistant. The vulnerability is tracked under CVE-2026-55145 and was disclosed by Microsoft.
Affected products
- Microsoft Copilot for Outlook All versions affected
Timeline
- 2026-07-14: advisory: Initial disclosure by Microsoft and NVD publication.