Home/Events/Microsoft 365 Copilot Vulnerability Exposed by Researchers

Microsoft 365 Copilot Vulnerability Exposed by Researchers

Resolved
Confidence
90%
Impact: 80%
Updated 1h ago

Consensus Brief

Researchers from Varonis discovered a critical vulnerability in Microsoft 365 Copilot that allowed attackers to exfiltrate user data, including passwords, without user consent. The exploit involved an undocumented prompt parameter that bypassed safety mechanisms, enabling automatic execution of commands when a malicious link was clicked.

Sourced from
Primary: Ars Technica

What Changed Since Last Update

1h ago

Microsoft has since mitigated the vulnerability by preventing the use of the undocumented parameter for injecting text into the chatbot input.

Claim Ledger

3 claims tracked across sources

Confirmed Fact

Researchers were able to extract user passwords and sensitive data from Microsoft 365 Copilot.

Confirmed Fact

The undocumented prompt parameter ?autorun=1 allowed for auto-execution of commands.

Confirmed Fact

Microsoft mitigated the vulnerability in February by changing how prompts are processed.

Role-Based Impact Analysis

Source Timeline

1 source corroborating