PT-2025-25212 · Microsoft · M365 Copilot
CVSS v3.1
9.3
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft 365 Copilot (affected versions not specified)
Description
EchoLeak is a critical zero-click vulnerability that allows an unauthorized remote attacker to exfiltrate sensitive organizational data from OneDrive, SharePoint, and Teams without any user interaction. The issue stems from a lack of data sanitization at the control level and LLM scope violations within the RAG (Retrieval-Augmented Generation) engine, which mixes untrusted inputs with internal data.
Exploitation occurs through a three-step chain: first, an attacker sends a crafted email containing hidden instructions designed to bypass prompt injection filters. Second, when a user queries Copilot for routine tasks, the system retrieves the malicious email via Microsoft Graph and follows the instructions to gather sensitive internal data. Third, the data is exfiltrated by embedding it in reference-style links or images; the Copilot interface then automatically fetches these external resources using a trusted Microsoft Teams proxy to bypass Content Security Policies (CSP) and send the encoded data to the attacker. The attack also utilizes ASCII smuggling to evade security policies.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability, as Microsoft has deployed automatic server-side updates for all cloud services, requiring no action from the user.
Fix
RCE
Command Injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
M365 Copilot