Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information disclosure locally.
The flaw lies in improper neutralization of special characters interpreted as commands (command injection). An attacker, without the need for authentication and user interaction, can submit crafted input data to the Copilot component. The vulnerability is exploited locally, however the scope of the breach extends beyond the direct context of the application (Scope: Changed), which increases the potential reach of the attack.
An attacker can gain unauthorized access to sensitive information processed by Microsoft 365 Copilot Chat. According to the CVSS vector, high impact on data confidentiality is possible while having limited impact on its integrity.
Apply patches available from the vendor according to the references — detailed information about available updates is available at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59272
Microsoft 365 Copilot Chat — versions indicated in the vendor's references
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:NMicrosoft 365 Copilot Chat
APPMicrosoftall versions
Related vulnerabilities
SSRF w Microsoft Exchange umożliwia eskalację uprawnień sieciowych
Command Injection w Microsoft 365 Copilot Chat umożliwiający ujawnienie informacji
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an ...
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an ...
Microsoft 365 Copilot BizChat Information Disclosure Vulnerability