When prompts become shells: RCE vulnerabilities in AI agent frameworks Microsoft