CVE-2026-42824
CVSS 6.5 MEDIUM: improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an… EPSS 0.9% (59º percentile).
AI · 103 giorni fa
Il punto debole non è solo Copilot che risponde troppo: è un link microsoft.com che porta istruzioni nascoste in un parametro consentito e passa oltre i controlli che cercano destinazioni sospette. In pratica, il filtro vede un dominio affidabile e perde di vista il contenuto che il link trasporta; il risultato è che il motore di ricerca AI può essere indotto a leggere e far uscire dati a cui l’utente ha accesso.
Varonis ha pubblicato un proof-of-concept per SearchLeak, la catena che Microsoft ha già mitigato lato backend e che ha ricevuto l’identificatore CVE-2026-42824. La catena combina un parameter-to-prompt injection nel parametro 'q', una race condition nel rendering HTML e un bypass della Content Security Policy tramite Bing; i dati in gioco includono email, calendario, documenti, OneDrive e SharePoint.
Per chi governa l’accesso a posta e contenuti in Microsoft 365 Copilot Enterprise, il problema da tenere a mente è questo: un link apparentemente legittimo può veicolare istruzioni eseguibili, non solo una ricerca. La finestra operativa è ora di consapevolezza e verifica, ma il modello di fiducia resta quello da correggere anche altrove, ogni volta che un assistente AI legge dati interni da un input che sembra innocuo.
CVSS 6.5 MEDIUM: improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an… EPSS 0.9% (59º percentile).
5 fonti che coprono questa storia
M365 Copilot SearchLeak: Your prompt injection attack surface just got bigger
Although not the first of its kind, researchers’ POC attack against Microsoft’s M365 Copilot Enterprise underscores parameter-to-prompt (P2P) injections as a potentially broad threat.
Critical Copilot vulnerability allowed hackers to steal 2FA code from users
SearchLeak exploit shows why the industry's approach to LLM security fails over and over.
One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes
Microsoft fixed a critical Copilot Enterprise Search flaw that could expose emails, calendars, and indexed files through one trusted link.
Copilot 'SearchLeak' Attack Allows 1-Click Data Theft
The critical, three-stage attack is now patched, but it's part of a new group of AI prompt-injection issues that use hidden URLs and other variables.
New attack turned Microsoft 365 Copilot into 1-click data theft tool
A critical vulnerability chain dubbed SearchLeak in Microsoft 365 Copilot Enterprise could allow attackers to steal sensitive data from a target's mailbox, OneDrive, or SharePoint account through a specially crafted URL.
Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-06-20