PT-2025-25212 · Microsoft · M365 Copilot

·

CVE-2025-32711

·

Published

2025-06-11

·

Updated

2026-07-20

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Microsoft 365 Copilot (affected versions not specified)
Description EchoLeak is a critical zero-click vulnerability that allows an unauthorized remote attacker to exfiltrate sensitive organizational data from OneDrive, SharePoint, and Teams without any user interaction. The issue stems from a lack of data sanitization at the control level and LLM scope violations within the RAG (Retrieval-Augmented Generation) engine, which mixes untrusted inputs with internal data.
Exploitation occurs through a three-step chain: first, an attacker sends a crafted email containing hidden instructions designed to bypass prompt injection filters. Second, when a user queries Copilot for routine tasks, the system retrieves the malicious email via Microsoft Graph and follows the instructions to gather sensitive internal data. Third, the data is exfiltrated by embedding it in reference-style links or images; the Copilot interface then automatically fetches these external resources using a trusted Microsoft Teams proxy to bypass Content Security Policies (CSP) and send the encoded data to the attacker. The attack also utilizes ASCII smuggling to evade security policies.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability, as Microsoft has deployed automatic server-side updates for all cloud services, requiring no action from the user.

Fix

RCE

Command Injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-06696
CVE-2025-32711

Affected Products

M365 Copilot