Critical flaw in Microsoft Copilot could have allowed zero-click attack
A critical zero-click vulnerability, dubbed "EchoLeak" and identified as CVE-2025-32711, was discovered in Microsoft Copilot. This flaw leveraged an "LLM scope violation" to allow remote attackers to exfiltrate sensitive data from Microsoft 365 services without any user interaction.
STABLE
What Happened
A critical zero-click vulnerability, dubbed "EchoLeak" and identified as CVE-2025-32711, was discovered in Microsoft Copilot. This flaw leveraged an "LLM scope violation" to allow remote attackers to exfiltrate sensitive data from Microsoft 365 services without any user interaction.
Why This Matters
Publisher reporting describes a security event affecting jun. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.
Recommended Action
Confirm whether jun is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.
Exposure
Exposure unknown
Jun 16, 2026 12:30
Exposure reason: This incident does not currently match a technology in My Interests.
Exploitation status: UNKNOWN
Primary entities:
Authoritative Intelligence
Public GitHub References
Search GitHub for public repositories that mention this CVE. BugSkan only lists repository metadata as a defensive awareness signal โ it does not fetch or display exploit code.
GitHub API error: API rate limit exceeded for 68.178.145.130. (But here's the good news: Authenticated requests get a higher rate limit. Check out the documentation for more details.)
Timeline
-
Incident first seen
Jun 11, 2025 05:30BugSkan first recorded this incident.
-
Critical flaw in Microsoft Copilot could have allowed zero-click attack - Cybersecurity Dive
Jun 11, 2025 05:30cybersecuritydive.com ยท Vulnerability
-
Zero-Click AI Vulnerability Exposes Microsoft 365 Copilot Data Without User Interaction - The Hacker News
Jun 12, 2025 05:30thehackernews.com ยท Vulnerability
-
Preventing Zero-Click AI Threats: Insights from EchoLeak - www.trendmicro.com
Jul 15, 2025 05:30trendmicro.com ยท Data Leak
-
CVE-2025-32711: Zero-Click 'EchoLeak' Vulnerability in Microsoft 365 Copilot Enables Stealth Data Exfiltration via Prompt Injection - Rescana
Jun 16, 2026 12:30news.google.com ยท Data Leak
-
Latest observed development
Jun 16, 2026 12:30Most recent source or update associated with this incident.
Sources
cybersecuritydive.com ยท Jun 11, 2025 05:30
A critical zero-click vulnerability, dubbed "EchoLeak" and identified as CVE-2025-32711, was discovered in Microsoft Copilot. This flaw leveraged an "LLM scope violation" to allow remote attackers to exfiltrate sensitive data from Microsoft 365 services without any user interaction.
Open publisher sourcethehackernews.com ยท Jun 12, 2025 05:30
A critical zero-click AI vulnerability, identified as EchoLeak (CVE-2025-32711, CVSS 9.3), allowed for unauthorized data exfiltration from Microsoft 365 Copilot without user interaction. This flaw leveraged an LLM Scope Violation and indirect prompt injection within markdown content to trick the AI's Retrieval-Augmented Generation (RAG) engine into leaking sensitive contextual data.
Open publisher sourcetrendmicro.com ยท Jul 15, 2025 05:30
EchoLeak (CVE-2025-32711) is a zero-click AI vulnerability that exploits Microsoft 365 Copilot's retrieval-augmented generation (RAG) capabilities. It leverages invisible prompt injections embedded in contextual data to silently exfiltrate sensitive information without user interaction.
Open publisher sourcenews.google.com ยท Jun 16, 2026 12:30
CVE-2025-32711: Zero-Click 'EchoLeak' Vulnerability in Microsoft 365 Copilot Enables Stealth Data Exfiltration via Prompt Injection Rescana
Open publisher sourceRelated Incidents
Other BugSkan incidents that share identifiers, products, or vendors with this report.
My Interests Match
Create an account to see which incidents overlap with your interests.