DNA View

High Severity Vulnerability

This vulnerability has been rated as High severity. Immediate action is recommended.

CVE-2025-64671

High
Low Medium High Critical
8.4
CVSS Score
Published: Dec 09, 2025
Last Modified: Dec 12, 2025

Vulnerability Description

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to execute code locally.

CVSS Metrics

Common Vulnerability Scoring System

Vector String:

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
L
Attack Complexity
L
Privileges Required
N
User Interaction
N
Scope
U
Confidentiality
H
Integrity
H
Availability
H

Severity Details

8.4
out of 10.0
High

Weakness Type (CWE)

CWE-77 Top 25 #9

Improper Neutralization of Special Elements used in a Command ('Command Injection')

Description
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Exploit Likelihood
High
Typical Severity
Medium
OWASP Top 10
A03:2021-Injection
Abstraction Level
Class

Key Information

Published Date
December 09, 2025

Related News Articles

Latest news and updates about CVE-2025-64671