CVE-2025-59252 | Microsoft 365 Word Copilot command injection
A vulnerability was found in Microsoft 365 Word Copilot. It has been classified as critical. The impacted element is an unknown function. This manipulation causes command injection.
The identification of this vulnerability is CVE-2025-59252. It is possible to initiate the attack remotely. There is no exploit available.
This product is a managed service. This means that users are not able to maintain vulnerability countermeasures themselves.