CVE-2026-85885
9.9Microsoft · Microsoft 365 Copilot
A command injection vulnerability in Microsoft 365 Copilot allows an authenticated attacker to elevate privileges over a network.
Executive summary
A critical command injection vulnerability in Microsoft 365 Copilot enables authenticated attackers to achieve unauthorized privilege escalation and full system compromise.
Vulnerability
This vulnerability is a command injection flaw (CWE-77) where improper neutralization of special elements allows an attacker with low-level privileges to execute arbitrary commands, leading to complete system compromise.
Business impact
The potential for successful exploitation is severe, as it grants an attacker full control over the affected environment, leading to data exfiltration, service disruption, and unauthorized administrative access. Given the CVSS score of 9.9, this vulnerability poses an extreme threat to organizational confidentiality, integrity, and availability.
Remediation
Immediate Action: Organizations should monitor the Microsoft Security Response Center (MSRC) update guide for the release of a security patch and apply it immediately upon availability.
Proactive Monitoring: Security teams should implement enhanced logging for command execution patterns and audit access logs for anomalous behavior originating from authenticated users.
Compensating Controls: Deploy Web Application Firewall (WAF) rules designed to detect and block malicious command injection patterns, although these should be considered temporary measures until a vendor patch is applied.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Due to the critical nature of this vulnerability and its potential for total system compromise, administrators must prioritize the monitoring of the vendor advisory for patch availability. Once a fix is released, it should be deployed with the highest urgency to mitigate the risk of unauthorized privilege escalation and network exploitation.
More Microsoft CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section
Sources
- Microsoft 365 Copilot Elevation of Privilege Vulnerability Vendor advisory