CVE-2025-64671

Publication date

2025-12-09 17:56:06

Family

microsoft

State

PUBLISHED

Description

Improper neutralization of special elements used in a command (command injection) in Copilot allows an unauthorized attacker to execute code locally.