Executive brief
Microsoft M365 Copilot, an AI assistant integrated into Microsoft 365 productivity applications, contains a command injection vulnerability that allows authorized users to execute arbitrary commands and escalate their privileges. An attacker with valid credentials could exploit this flaw to gain elevated access within the M365 environment, potentially compromising sensitive organizational data and systems.
Technical details
A command injection vulnerability in M365 Copilot fails to properly neutralize special elements in user-supplied input, allowing authenticated attackers to inject and execute arbitrary system commands. The vulnerability can be exploited over the network by an authorized user to escalate privileges beyond their normal account permissions. A patch from Microsoft is expected to address this issue.
Affected products
- Microsoft M365 Copilot
Timeline
- 2026-09-17: disclosed