Copilot AI Flaw Allows Attackers to Steal Sensitive Information
A vulnerability in Microsoft's Copilot AI assistant has been discovered by researchers at Varonis. The flaw allows attackers to inject malicious prompts into Copilot, which can then be executed without user approval.
The researchers found that by adding a specific parameter to the URL of a prompt, they could bypass the usual protection mechanisms and inject a command directly into Copilot. This allowed them to access sensitive information such as email addresses and credentials stored in the victim's account.
Copilot is designed to be used within the Microsoft 365 suite, which includes tools like Outlook and OneDrive. The researchers demonstrated that an attacker could send a malicious URL to a user via email or chat, which would then execute on the user's device when clicked. This allowed the attackers to steal sensitive information and exfiltrate it to their own server.
The Varonis researchers also discovered another attack vector, where an attacker could inject malicious prompts into Copilot through a webpage. This allowed them to update the permanent memory store of Copilot, which stores user preferences and instructions for future sessions. The attackers could use this vulnerability to forward outputs, filter information, or execute specific actions on trigger conditions.
The researchers published their findings in a blog post on Tuesday, detailing the steps involved in exploiting these vulnerabilities. They emphasize that these attacks are not hypothetical, but have been demonstrated and tested against Copilot.