Microsoft Copilot Rooted to Gain Unauthorized Root Access to its Backend System
ID: 7b96ee21-1494-5b1d-a4f3-091c299ca078
STIX ID: report--7b96ee21-1494-5b1d-a4f3-091c299ca078
Feed Name: cybersecurityNews.com
A Jupyter-backed live Python sandbox introduced to Microsoft Copilot Enterprise in April 2025 contained a PATH-based pgrep invocation in the root entrypoint that researchers from Eye Security exploited by uploading a malicious pgrep binary into a writable conda path; this allowed arbitrary command execution as root inside the backend container, enabled access to files via blob links and hinted at potential further access to internal services via OAuth abuse. Microsoft was notified on April 18, 2025, and fixed the vulnerability by July 25, classifying it as moderate severity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
