Rogue Agent Watch › Records › echoleak-m365-copilot

EchoLeak — zero-click prompt injection in Microsoft 365 Copilot

Disclosed · added to the index · last updated

Grades

Verification status
Confirmed — Confirmed by a first-party disclosure or multiple independent credible sources.
Sourcing confidence
Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
AI role
Load-bearing — AI was central — the operation as described could not have happened at this scale or in this form without it.
Severity
Critical — Broad real-world harm — e.g. many organizations compromised, large-scale exfiltration, or critical-infrastructure impact.

Summary

Aim Labs (Aim Security) disclosed EchoLeak, assigned CVE-2025-32711, a zero-click indirect prompt-injection vulnerability in Microsoft 365 Copilot. A single crafted email could cause the retrieval-augmented Copilot agent to pull sensitive organisational data from the user's context and exfiltrate it with no user interaction. Aim Labs termed the underlying class "LLM Scope Violation." Microsoft patched it server-side and states no customers were affected.

Impact as stated

Demonstrated zero-click exfiltration of data from the Microsoft 365 Copilot context (chat history, Microsoft Graph resources and preloaded context). Mitigated server-side by Microsoft with no reported in-the-wild exploitation.

Facts as stated by sources

Actor
Aim Labs (Aim Security) (Researcher)
Category
Agent hijack / prompt injection
Models named
GPT-4
Model families
GPT (OpenAI)
Agentic autonomy level
Not applicable
Guardrail bypass
Indirect prompt injection
Attack lifecycle phases
Initial access, Execution, Exfiltration
Target sectors
not stated
Target countries
not stated
Organisations affected
0
Records exfiltrated
not stated

Framework mappings

MITRE ATLAS
AML.T0051.001, AML.T0057
OWASP LLM Top 10
LLM01
CVE
CVE-2025-32711

Mitigations as stated

  • Microsoft mitigated the vulnerability server-side; no customer action was required.

Map

No cited source states a location; this record is listed beside the map, never plotted.

Related records

Sources (3)

  1. Breaking down 'EchoLeak', the First Zero-Click AI Vulnerability Enabling Data Exfiltration from Microsoft 365 Copilot
    Cato Networks (Aim Labs) · First-party disclosure · · archived copy
  2. CVE-2025-32711 Detail
    NVD / NIST · Government advisory · · archived copy
  3. 'EchoLeak' AI Attack Enabled Theft of Sensitive Data via Microsoft 365 Copilot
    SecurityWeek · News · · archived copy

Cite this record

Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "echoleak-m365-copilot". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/echoleak-m365-copilot.json — CC BY-SA 4.0.

Record JSON · Source YAML · Report a correction