Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.
The vulnerability consists of improper neutralization of special characters used in commands (command injection) in the Copilot component. An attacker can craft appropriate input data passed to the vulnerable command processing mechanism without needing to possess an account or permissions. Successful exploitation of the vulnerability leads to unauthorized information disclosure in a context that exceeds system boundaries (Scope: Changed).
An unauthenticated remote attacker can gain unauthorized access to sensitive information processed by Microsoft 365 Copilot Chat, potentially including user and organizational data. The vulnerability does not enable direct data modification or disruption of service availability.
Apply patches available from the vendor in accordance with references published by Microsoft Security Response Center at: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59286. As a supplementary measure, it is recommended to monitor access to Microsoft 365 Copilot Chat services and limit exposure to external input data where possible.
Microsoft 365 Copilot Chat — versions indicated in vendor references (Microsoft Security Response Center).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:NMicrosoft 365 Copilot Chat
APPMicrosoftall versions
Related vulnerabilities
SSRF w Microsoft Exchange umożliwia eskalację uprawnień sieciowych
Command injection w Microsoft 365 Copilot Chat umożliwiający ujawnienie informacji
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an ...
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an ...
Microsoft 365 Copilot BizChat Information Disclosure Vulnerability