PulseAugur
EN
LIVE 14:56:29

Microsoft Copilot vulnerability allowed data exfiltration without user consent

Security researchers discovered a vulnerability in Microsoft 365 Copilot Enterprise that allowed them to bypass user consent requirements and exfiltrate sensitive data. By engaging in a question-and-answer session with Copilot, the researchers were able to uncover an undocumented prompt parameter, '?autorun=1', which, when combined with a known parameter, enabled malicious links to trigger data exfiltration automatically. Microsoft has since patched the vulnerability, first mitigating it in February and implementing more comprehensive fixes recently. AI

IMPACT This incident highlights the ongoing security challenges with AI assistants and the need for robust consent mechanisms to prevent unauthorized data access.

RANK_REASON The article details a security vulnerability in a specific AI-powered product, Microsoft 365 Copilot Enterprise, and its subsequent mitigation.

Read on Ars Technica — AI →

AI-generated summary · Google Gemini · from 1 sources. How we write summaries →

Microsoft Copilot vulnerability allowed data exfiltration without user consent

COVERAGE [1]

  1. Ars Technica — AI TIER_1 English(EN) · Dan Goodin ·

    Microsoft Copilot reveals secret input that allowed it to be hacked

    Secret parameter allowed hackers to steal passwords when a target clicked on a link.