A vulnerability on Microsoft 365 Copilot may have been email stolen.
A vulnerability was found on Microsoft 365 Copilot that could allow hackers to steal emails.
According to a report by the website, The Hacker News mentioned the detection of a bug on the AI Copilot for Microsoft 365 tool that allows hackers to retrieve emails, calendars, and Index files via Microsoft 365 Copilot Enterprise Search in a single click without requiring a Prompt or Password. In addition, the Exfiltration section points directly to the Microsoft domain, making the URL Filter and Anti-Phishing systems unable to intercept. The vulnerability was named SearchLeak under the code CVE-2026-42824, but the part of the danger score, or CVSS Score, was inconclusive because Microsoft gave it a very low score of 6.5, while the National Vulnerability Database gave it a high score of 7.5.
According to Microsoft's research team, this vulnerability is a command firing type vulnerability, or Command Injection, in the Parameter q section of the Copilot Enterprise Search URL. The research team from Varonis, a data security and AI systems expert, has redefined it as a Parameter-to-Prompt Injection vulnerability. Hackers can create URLs that instruct the AI to navigate the mailbox, order the Email Title, and place it secretly in the URL of the image. Trick the victim to click. The AI will then navigate the data inside the email box. Come out
There is another factor to consider in this security vulnerability: Race Condition. Copilot has a guardrail. The output block is only a normal Text, so it relies on the tempo to shoot the tag down before the Sanitization works. The output that the hacker will receive is according to the hacker's intention. In addition, the output block can be passed through the Content Control Policy or the Content Security Policy (CSP). This policy is enforced on m365.cloud.microsoft will block images from other domains, but accept images from * .bing.com. If hackers use the "Search by Image" feature to extract image data to analyze on Microsoft's servers, the CSP policy will not work. Bing can be used as an exporting agent.
In summary, this operation is that when a hacker tricks the victim into pressing the link, the Copilot will start searching for the information defined on the link. The Copilot will then create a response link in Bing's image URL to send it back. The web browser will then run Bing during the streaming. Bing will pull out the hacker's URL, allowing the hacker to read the log from that URL, such as the request for Your _ Security _ Code _ 847291 / img.png, etc.
Important information that can be stolen by hackers using this method covers a variety of types of information inside the victim's email box, such as OTP or One-Time Password, MFA or Multi-Factors Authentication, and Password Reset links. Copilot can also be accessed on Microsoft 365, such as Calendar Invite, Conference Notes, and a lot of information. It is a very dangerous vulnerability despite its relatively low seriousness rating.
# microsoftcopilot # microsoft # Trending # lemon 8 diary # freedomhack
จากประสบการณ์ในการติดตามรายงานช่องโหว่ของระบบ Microsoft 365 ที่เกี่ยวข้องกับ AI Copilot พบว่า SearchLeak เป็นกรณีศึกษาที่สำคัญที่แสดงให้เห็นถึงความเสี่ยงของการใช้ AI ที่ผนวกในเครื่องมือองค์กร โดยเฉพาะอย่างยิ่งกับฟีเจอร์ Copilot Enterprise Search ที่เปิดโอกาสให้เกิดการโจมตีแบบ Parameter-to-Prompt Injection ได้ง่ายมาก เพราะแฮกเกอร์สามารถสร้าง URL ที่ฝังคำสั่งเพื่อสั่งให้ AI ดึงข้อมูลสำคัญจากกล่องจดหมายของเหยื่อได้ทันที แม้กระทั่งข้อมูลรหัส OTP, ข้อมูล MFA หรือแม้แต่ลิงก์รีเซ็ตรหัสผ่าน ซึ่งถือเป็นภัยคุกคามที่รุนแรงต่อความปลอดภัยทางไซเบอร์ขององค์กร สิ่งที่น่าสนใจคือช่องโหว่นี้ยังใช้ประโยชน์จากนโยบาย Content Security Policy (CSP) ของ Microsoft ที่อนุญาตให้โหลดรูปภาพจากโดเมน bing.com ซึ่งเป็นการเปิดช่องให้แฮกเกอร์ใช้ Bing เป็นตัวกลางในการส่งข้อมูลที่ถูกขโมยออกไปโดยที่ระบบป้องกันแบบเดิมไม่สามารถตรวจจับหรือบล็อกได้ ในแง่ของเทคนิค ผู้โจมตีต้องอาศัยเทคนิค Race Condition เพื่อกินช่วงเวลาที่ระบบยังไม่ทำการ Sanitization ก่อนที่จะส่งผลลัพธ์กลับออกมาเป็น URL ของรูปภาพเพื่อซ่อนข้อมูลที่ถูกขโมยไว้ จากประสบการณ์ส่วนตัวถ้าเป็นผู้ใช้หรือผู้ดูแลระบบที่เกี่ยวข้องกับ Microsoft 365 ควรรีบรักษามาตรการความปลอดภัยขั้นสูง เช่น การเปิดใช้งาน Multi-Factor Authentication (MFA) อย่างเต็มรูปแบบ ตรวจสอบและจำกัดสิทธิ์ของผู้ใช้งานในระดับสูงสุด รวมถึงติดตามอัพเดตแพตช์ที่ Microsoft ออกมาแก้ไขช่องโหว่ดังกล่าวอย่างสม่ำเสมอ เพราะแม้คะแนนความร้ายแรงที่ Microsoft ให้มาต่ำ แต่การที่ช่องโหว่สามารถนำไปสู่การขโมยข้อมูลสำคัญภายในองค์กรได้อย่างง่ายดายนั้นถือว่าเป็นความเสี่ยงที่สูงมาก นอกจากนี้ยังแนะนำให้เพิ่มการตรวจสอบการใช้งาน Copilot และบริการของ Microsoft 365 ผ่านเครื่องมือวิเคราะห์การเข้าถึง (Access Analytics) เพื่อให้เห็นพฤติกรรมที่ผิดปกติ เช่น การเรียก URL ที่มีพารามิเตอร์แปลกๆ หรือการตอบกลับ URL รูปภาพที่น่าสงสัย เพื่อป้องกันความเสียหายที่อาจเกิดขึ้นได้จากช่องโหว่นี้
