Rogue Agent Watch › Records › echoleak-m365-copilot
EchoLeak — zero-click prompt injection in Microsoft 365 Copilot
Disclosed · added to the index · last updated
Grades
- Verification status
- Confirmed — Confirmed by a first-party disclosure or multiple independent credible sources.
- Sourcing confidence
- Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
- AI role
- Load-bearing — AI was central — the operation as described could not have happened at this scale or in this form without it.
- Severity
- Critical — Broad real-world harm — e.g. many organizations compromised, large-scale exfiltration, or critical-infrastructure impact.
Summary
Aim Labs (Aim Security) disclosed EchoLeak, assigned CVE-2025-32711, a zero-click indirect prompt-injection vulnerability in Microsoft 365 Copilot. A single crafted email could cause the retrieval-augmented Copilot agent to pull sensitive organisational data from the user's context and exfiltrate it with no user interaction. Aim Labs termed the underlying class "LLM Scope Violation." Microsoft patched it server-side and states no customers were affected.
Impact as stated
Demonstrated zero-click exfiltration of data from the Microsoft 365 Copilot context (chat history, Microsoft Graph resources and preloaded context). Mitigated server-side by Microsoft with no reported in-the-wild exploitation.
Facts as stated by sources
- Actor
- Aim Labs (Aim Security) (Researcher)
- Category
- Agent hijack / prompt injection
- Models named
- GPT-4
- Model families
- GPT (OpenAI)
- Agentic autonomy level
- Not applicable
- Guardrail bypass
- Indirect prompt injection
- Attack lifecycle phases
- Initial access, Execution, Exfiltration
- Target sectors
- not stated
- Target countries
- not stated
- Organisations affected
- 0
- Records exfiltrated
- not stated
Framework mappings
- MITRE ATLAS
- AML.T0051.001, AML.T0057
- OWASP LLM Top 10
- LLM01
- CVE
- CVE-2025-32711
Mitigations as stated
- Microsoft mitigated the vulnerability server-side; no customer action was required.
Map
No cited source states a location; this record is listed beside the map, never plotted.
Related records
Sources (3)
- Breaking down 'EchoLeak', the First Zero-Click AI Vulnerability Enabling Data Exfiltration from Microsoft 365 Copilot
Cato Networks (Aim Labs) · First-party disclosure · · archived copy - CVE-2025-32711 Detail
NVD / NIST · Government advisory · · archived copy - 'EchoLeak' AI Attack Enabled Theft of Sensitive Data via Microsoft 365 Copilot
SecurityWeek · News · · archived copy
Cite this record
Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "echoleak-m365-copilot". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/echoleak-m365-copilot.json — CC BY-SA 4.0.