Last seen June 16, 2026

Critical flaw in Microsoft Copilot could have allowed zero-click attack

A critical zero-click vulnerability, dubbed "EchoLeak" and identified as CVE-2025-32711, was discovered in Microsoft Copilot. This flaw leveraged an "LLM scope violation" to allow remote attackers to exfiltrate sensitive data from Microsoft 365 services without any user interaction.

Technical Severity
Low severity
Lifecycle Status

STABLE

What Happened

A critical zero-click vulnerability, dubbed "EchoLeak" and identified as CVE-2025-32711, was discovered in Microsoft Copilot. This flaw leveraged an "LLM scope violation" to allow remote attackers to exfiltrate sensitive data from Microsoft 365 services without any user interaction.

Why This Matters

Publisher reporting describes a security event affecting jun. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.

Recommended Action

Confirm whether jun is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.

Exposure

My Interests Exposure

Exposure unknown

Recommended Response
Last Seen

Jun 16, 2026 12:30

Exposure reason: This incident does not currently match a technology in My Interests.

Exploitation status: UNKNOWN

Primary entities:

MicrosoftMicrosoft CopilotData LeakagePrompt InjectionSupply ChainCritical

Authoritative Intelligence

CVE CVE-2025-32711 Incident identifier

EPSS is a vulnerability exploitation probability signal, not proof that your environment is exposed. CISA KEV means known exploitation of the vulnerability, not that your system was exploited.

Public GitHub References

Search GitHub for public repositories that mention this CVE. BugSkan only lists repository metadata as a defensive awareness signal โ€” it does not fetch or display exploit code.

Timeline

  • Incident first seen
    Jun 11, 2025 05:30

    BugSkan first recorded this incident.

  • Critical flaw in Microsoft Copilot could have allowed zero-click attack - Cybersecurity Dive
    Jun 11, 2025 05:30

    cybersecuritydive.com ยท Vulnerability

  • Zero-Click AI Vulnerability Exposes Microsoft 365 Copilot Data Without User Interaction - The Hacker News
    Jun 12, 2025 05:30

    thehackernews.com ยท Vulnerability

  • Preventing Zero-Click AI Threats: Insights from EchoLeak - www.trendmicro.com
    Jul 15, 2025 05:30

    trendmicro.com ยท Data Leak

  • CVE-2025-32711: Zero-Click 'EchoLeak' Vulnerability in Microsoft 365 Copilot Enables Stealth Data Exfiltration via Prompt Injection - Rescana
    Jun 16, 2026 12:30

    news.google.com ยท Data Leak

  • Latest observed development
    Jun 16, 2026 12:30

    Most recent source or update associated with this incident.

Sources

Critical flaw in Microsoft Copilot could have allowed zero-click attack - Cybersecurity Dive

cybersecuritydive.com ยท Jun 11, 2025 05:30

A critical zero-click vulnerability, dubbed "EchoLeak" and identified as CVE-2025-32711, was discovered in Microsoft Copilot. This flaw leveraged an "LLM scope violation" to allow remote attackers to exfiltrate sensitive data from Microsoft 365 services without any user interaction.

Open publisher source
Zero-Click AI Vulnerability Exposes Microsoft 365 Copilot Data Without User Interaction - The Hacker News

thehackernews.com ยท Jun 12, 2025 05:30

A critical zero-click AI vulnerability, identified as EchoLeak (CVE-2025-32711, CVSS 9.3), allowed for unauthorized data exfiltration from Microsoft 365 Copilot without user interaction. This flaw leveraged an LLM Scope Violation and indirect prompt injection within markdown content to trick the AI's Retrieval-Augmented Generation (RAG) engine into leaking sensitive contextual data.

Open publisher source
Preventing Zero-Click AI Threats: Insights from EchoLeak - www.trendmicro.com

trendmicro.com ยท Jul 15, 2025 05:30

EchoLeak (CVE-2025-32711) is a zero-click AI vulnerability that exploits Microsoft 365 Copilot's retrieval-augmented generation (RAG) capabilities. It leverages invisible prompt injections embedded in contextual data to silently exfiltrate sensitive information without user interaction.

Open publisher source
CVE-2025-32711: Zero-Click 'EchoLeak' Vulnerability in Microsoft 365 Copilot Enables Stealth Data Exfiltration via Prompt Injection - Rescana

news.google.com ยท Jun 16, 2026 12:30

CVE-2025-32711: Zero-Click 'EchoLeak' Vulnerability in Microsoft 365 Copilot Enables Stealth Data Exfiltration via Prompt Injection Rescana

Open publisher source

Other BugSkan incidents that share identifiers, products, or vendors with this report.

My Interests Match

Want personalized relevance?

Create an account to see which incidents overlap with your interests.

โ† Back to incident intelligence