A vulnerability, which was classified as critical, was found in Microsoft 365 Copilot. This affects an unknown part of the component AI Handler. The manipulation leads to command injection.
This vulnerability is uniquely identified as CVE-2025-32711. It is possible to initiate the attack remotely. There is no exploit available.
This product is a managed service. This means that users are not able to maintain vulnerability countermeasures themselves.