RESEARCHERS from Varonis demonstrated a critical vulnerability in Microsoft 365 Copilot Enterprise, allowing it to exfiltrate user data like passwords without user consent. By iteratively questioning Copilot, they discovered an undocumented parameter, ?autorun=1, which bypassed safety mechanisms and enabled automatic execution of prompts upon clicking malicious links. This exploit could retrieve sensitive data, including email addresses and passwords, and send it to an attacker-controlled server.
Although Microsoft has since mitigated this vulnerability, it highlights the risks associated with AI assistants, urging users to remain cautious with untrusted links and monitor outputs for anomalies. Furthermore, Varonis revealed another attack that could corrupt Copilot's memory, further exposing users to risks.