logo

Microsoft Copilot Rooted to Gain Unauthorized Root Access to its Backend System

ID: 7b96ee21-1494-5b1d-a4f3-091c299ca078

STIX ID: report--7b96ee21-1494-5b1d-a4f3-091c299ca078

Feed Name: cybersecurityNews.com

Threat Score
55/100

Date Published: 2025-07-25

Date Updated: 2026-04-21

Author: Guru Baran

...
...

A Jupyter-backed live Python sandbox introduced to Microsoft Copilot Enterprise in April 2025 contained a PATH-based pgrep invocation in the root entrypoint that researchers from Eye Security exploited by uploading a malicious pgrep binary into a writable conda path; this allowed arbitrary command execution as root inside the backend container, enabled access to files via blob links and hinted at potential further access to internal services via OAuth abuse. Microsoft was notified on April 18, 2025, and fixed the vulnerability by July 25, classifying it as moderate severity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.