CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-59272

CVSS 9.3v3.1pub. 2025-10-09upd. 2025-12-11

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information disclosure locally.

🤖 AI Analysis
How it works

The flaw lies in improper neutralization of special characters interpreted as commands (command injection). An attacker, without the need for authentication and user interaction, can submit crafted input data to the Copilot component. The vulnerability is exploited locally, however the scope of the breach extends beyond the direct context of the application (Scope: Changed), which increases the potential reach of the attack.

Impact

An attacker can gain unauthorized access to sensitive information processed by Microsoft 365 Copilot Chat. According to the CVSS vector, high impact on data confidentiality is possible while having limited impact on its integrity.

Mitigation & patch

Apply patches available from the vendor according to the references — detailed information about available updates is available at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59272

Who is affected

Microsoft 365 Copilot Chat — versions indicated in the vendor's references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
  • Microsoft 365 Copilot Chat

    APP
    Microsoft
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-26137CRITICAL9.9PL ✓same product

SSRF w Microsoft Exchange umożliwia eskalację uprawnień sieciowych

CVE-2025-59286CRITICAL9.3PL ✓same product

Command Injection w Microsoft 365 Copilot Chat umożliwiający ujawnienie informacji

CVE-2026-26129HIGH7.5same product

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an ...

CVE-2026-26164HIGH7.5same product

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an ...

CVE-2025-53787HIGH8.2same product

Microsoft 365 Copilot BizChat Information Disclosure Vulnerability