Microsoft finally patches critical one-click Copilot vulnerability, almost eight months after learning of it

Summary

Microsoft has patched a critical vulnerability in its personal Copilot AI assistant, nearly eight months after being notified. The "CoSnitch" vulnerability allowed attackers to exfiltrate data by exploiting an LLM's inability to distinguish queries from instructions and could lead to persistent memory poisoning. This is the third Copilot bug reported by Varonis this year, following Reprompt and SearchLeak, all sharing a similar exploit pattern.

IFF Assessment

FOE

This vulnerability allowed for data exfiltration and persistent memory poisoning, posing a significant risk to users and their data.

Severity

8.8 High

Defender Context

This article highlights the ongoing risks associated with AI assistants and LLMs, specifically prompt injection attacks that can lead to data exfiltration and persistent compromise. Defenders should be aware of such vulnerabilities in AI-powered tools and emphasize secure configurations and user education against suspicious links.

Read Full Story →