CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-59286

CVSS 9.3v3.1pub. 2025-10-09upd. 2025-12-11

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.

🤖 AI Analysis
How it works

The vulnerability consists of improper neutralization of special characters used in commands (command injection) in the Copilot component. An attacker can craft appropriate input data passed to the vulnerable command processing mechanism without needing to possess an account or permissions. Successful exploitation of the vulnerability leads to unauthorized information disclosure in a context that exceeds system boundaries (Scope: Changed).

Impact

An unauthenticated remote attacker can gain unauthorized access to sensitive information processed by Microsoft 365 Copilot Chat, potentially including user and organizational data. The vulnerability does not enable direct data modification or disruption of service availability.

Mitigation & patch

Apply patches available from the vendor in accordance with references published by Microsoft Security Response Center at: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59286. As a supplementary measure, it is recommended to monitor access to Microsoft 365 Copilot Chat services and limit exposure to external input data where possible.

Who is affected

Microsoft 365 Copilot Chat — versions indicated in vendor references (Microsoft Security Response Center).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
  • Microsoft 365 Copilot Chat

    APP
    Microsoft
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-26137CRITICAL9.9PL ✓same product

SSRF w Microsoft Exchange umożliwia eskalację uprawnień sieciowych

CVE-2025-59272CRITICAL9.3PL ✓same product

Command injection w Microsoft 365 Copilot Chat umożliwiający ujawnienie informacji

CVE-2026-26129HIGH7.5same product

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an ...

CVE-2026-26164HIGH7.5same product

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an ...

CVE-2025-53787HIGH8.2same product

Microsoft 365 Copilot BizChat Information Disclosure Vulnerability