PT-2025-25212 · Microsoft · M365 Copilot
CVSS v3.1
9.3
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft 365 Copilot (affected versions not specified)
Description
EchoLeak is a critical zero-click vulnerability that allows an unauthorized remote attacker to exfiltrate sensitive organizational data from Microsoft 365 Copilot without any user interaction. The issue stems from a lack of data cleansing at the management level and LLM scope violations within the RAG (Retrieval-Augmented Generation) engine, which mixes untrusted inputs with internal data.
The attack is executed through a three-step chain: first, the attacker sends a crafted email containing hidden instructions designed to bypass prompt injection filters. Second, when the system processes the email via Microsoft Graph, it follows these instructions to retrieve sensitive internal data from the user's mailbox, SharePoint documents, OneDrive files, and Teams chat history. Third, the data is exfiltrated by embedding it in reference-style links or images, using a Microsoft Teams proxy to bypass Content Security Policies (CSP) and send the encoded information to the attacker.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Command Injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
M365 Copilot