Information Disclosure Vulnerability in Microsoft 365 Copilot BizChat
CVE-2025-53774

6.5MEDIUM

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
7 August 2025

What is CVE-2025-53774?

An information disclosure vulnerability exists in Microsoft 365 Copilot BizChat, potentially exposing sensitive data to unauthorized users. This flaw can be exploited, allowing attackers to gain access to confidential information shared through the platform. Therefore, organizations using Microsoft 365 should implement security best practices and monitor for any potential exploit attempts. For detailed information and remediation guidance, please refer to the vendor's advisory.

Affected Version(s)

Microsoft 365 Copilot's Business Chat Unknown

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-53774 : Information Disclosure Vulnerability in Microsoft 365 Copilot BizChat