CVE-2025-32711
9.3
CRITICAL · CVSS 3.1 · EPSS 8% (pctl 95)
In your normal cycle
Critical by CVSS (9.3), but no sign of active exploitation.
Description
Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
Scoring
| CVSS | 9.3 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N |
| EPSS | 8.03% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-74 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2025-06-11 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| microsoft | 365 copilot |
References
→ the Explorer · watch your stack · NVD