Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-55145

Опубликовано: 14 июл. 2026
Источник: msrc
CVSS3: 6.3
EPSS Низкий

Описание

Outlook Copilot Tampering Vulnerability

Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authorized attacker to perform tampering over a network.

FAQ

How do I protect myself from this vulnerability?

Customers can help protect themselves by enabling Outlook's external sender tagging feature to identify untrusted content. This enables Microsoft's provided mitigations to isolate and safely process the untrusted content before it is provided to Microsoft 365 Copilot. Administrators can enable external sender tagging through Exchange Online PowerShell. Refer to the Microsoft Learn documentation for setup instructions and requirements.

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

N/A

EPSS

Процентиль: 30%
0.0037
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.3
nvd
17 дней назад

Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authorized attacker to perform tampering over a network.

CVSS3: 6.3
github
17 дней назад

Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authorized attacker to perform tampering over a network.

CVSS3: 6.3
fstec
18 дней назад

Уязвимость интеллектуального виртуального помощника почтового клиента Microsoft Outlook Copilot, позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 30%
0.0037
Низкий

6.3 Medium

CVSS3