Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

EchoLeak was a real vulnerability in Microsoft 365 Copilot, not merely a prompt-injection thought experiment. Tracked as CVE-2025-32711, it allowed a specially crafted message to manipulate Copilot into retrieving information available in a victim’s Microsoft 365 context and sending it toward attacker-controlled infrastructure without the victim opening the message or clicking a link. Microsoft says it deployed a server-side fix in May 2025, found no evidence of exploitation in the wild, and required no customer action for this specific vulnerability. The broader risk—untrusted content being interpreted as instructions by an AI assistant with access to business data—remains.

The essential facts

Item What is established
Name EchoLeak, a name used by Aim Security
Identifier CVE-2025-32711
Affected service Microsoft 365 Copilot, not every Microsoft product branded “Copilot”
Reported to Microsoft January 2025, according to the AAAI case study
Server-side remediation Deployed before public disclosure, reportedly in May 2025
Public disclosure June 11, 2025
User interaction in the demonstration No opening, clicking, or deliberate Copilot interaction was required
Exploitation status Microsoft said it found no evidence of in-the-wild exploitation
Customer action for this CVE Microsoft said no customer action was required

“First zero-click AI exploit” should be read narrowly. Aim Security and later technical analyses describe EchoLeak as the first publicly documented zero-click prompt-injection vulnerability demonstrated against a production large-language-model application—not the first AI vulnerability or the first zero-click attack of any kind.

Sources: Aim Security, AAAI paper, and Microsoft’s MSRC advisory.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What EchoLeak was

EchoLeak was an indirect prompt-injection and information-disclosure flaw. The attacker did not need to compromise a Microsoft 365 server or install malware. Instead, attacker-controlled instructions were hidden in content that Copilot was expected to read as data, such as an email.

That distinction matters. Microsoft 365 Copilot can ground responses in information the signed-in user is authorized to access across services such as Outlook, OneDrive, SharePoint, Office files, and Teams, subject to tenant configuration and indexing. EchoLeak abused the boundary between that retrieved content and the instructions governing the model.

How the zero-click attack chain worked

The public material describes a working proof of concept. The following is a conceptual explanation, not a reusable exploit payload.

  1. Crafted content arrives. An attacker sends specially constructed email or other content that the relevant Copilot workflow can retrieve or process.
  2. Instructions are mixed with ordinary text. The malicious text is designed to influence the model while appearing to be part of the material it is reading.
  3. Copilot adds the content to its working context. The model processes the attacker’s text alongside the user’s legitimate request and permitted Microsoft 365 sources.
  4. The injected instructions redirect the task. Rather than only summarizing or answering, Copilot is induced to search for information in the user’s accessible context.
  5. Extracted data is put into an automatically fetched resource. The demonstration used an image or similar external resource whose URL could carry the extracted content.
  6. A Microsoft-hosted proxy or preview path helps the request reach outside systems. Aim Security and the AAAI paper describe abuse of an allowed Microsoft domain and a Teams asynchronous preview mechanism to proxy the request.
  7. Data leaves without a victim click. Automatic processing and fetching complete the chain, which is why the researchers called it zero-click.

The relevant pipeline still had to process the content. “Zero-click” does not mean every tenant was continuously exposed; it means the demonstrated victim did not have to open the message or knowingly invoke Copilot for the chain to operate.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What information could be targeted?

The practical scope was bounded by the victim’s identity, permissions, connected repositories, indexing, labels, and tenant settings. It was not an automatic read of every file in every Microsoft 365 tenant.

  • Outlook mail and attachments
  • OneDrive files and Office documents
  • SharePoint pages and documents
  • Microsoft Teams conversations and shared files
  • Other Microsoft Graph-connected work data available to the Copilot context

A useful distinction is between data Copilot could reach under the user’s permissions and data researchers demonstrated extracting in the proof of concept. EchoLeak did not necessarily bypass ordinary authorization. It could make an assistant collect and transmit information that the user could already access—potentially turning existing oversharing into a much faster discovery and exfiltration path.

Why existing defenses were insufficient

The case exposed a confused trust boundary: the application treated retrieved material as untrusted data, while the model could interpret text inside that material as instructions. Aim Security and the AAAI analysis describe a chain that could evade or work around several expected safeguards:

  • Cross-prompt-injection classifiers
  • External-link redaction
  • Content Security Policy restrictions
  • Copilot reference and citation behavior
  • Assumptions that retrieved text remains passive data

Filtering at the model layer is therefore only one control. A system can reject obvious “ignore previous instructions” text yet still be influenced by obfuscated, contextual, or novel instructions embedded in a document or email. Protection has to span ingestion, retrieval, authorization, rendering, outbound networking, and monitoring.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft’s current Defender for Office 365 prompt-injection guidance specifically addresses concealed email content such as white-on-white text, zero-size text, off-screen elements, and HTML/CSS tricks intended for an AI system rather than a human reader.

What Microsoft fixed—and what it did not claim

Microsoft’s MSRC entry says the remediation was server-side and that no customer action was required for CVE-2025-32711. That means customers should not search for a nonexistent EchoLeak installer or CVE-specific command.

Microsoft also stated that it had found no evidence of exploitation in the wild. Aim Security demonstrated exploitability; that is different from proving that criminals used the technique against customers. “Could exfiltrate data” and “did exfiltrate customer data” are not interchangeable claims.

Fixing the specific vulnerability does not eliminate indirect prompt injection as a class. Microsoft 365 Copilot is a cloud service, and the incident does not automatically apply to consumer Microsoft Copilot, Security Copilot, GitHub Copilot, Copilot Studio agents, or third-party assistants.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What Microsoft 365 administrators should do now

No emergency patch is required for the fixed CVE, but organizations expanding or operating Copilot should treat this as a data-governance and trust-boundary issue.

  1. Confirm service status. Review Microsoft 365 service health and security communications, and verify that no legacy or disconnected Copilot integration remains in use.
  2. Harden the inbox. Review Defender for Office 365 prompt-injection protections, quarantine policies, Safe Links, and investigation workflows.
  3. Find oversharing. Audit SharePoint, OneDrive, Teams, and Exchange permissions; remove stale access and unnecessary external sharing.
  4. Classify sensitive information. Use Microsoft Purview sensitivity labels, DLP, data-security-posture tools, insider-risk workflows, and audit features as appropriate. Microsoft’s Copilot security guidance explains the available controls.
  5. Govern agents and connectors. Record which agents, plugins, third-party connectors, and external services can retrieve data or take actions. Define who can enable or disable them.
  6. Monitor egress and identity activity. Alert on unusual outbound requests, anomalous mailbox or file access, suspicious proxy use, and unexpected AI-generated activity.
  7. Test response procedures. Ensure logs from Copilot, Exchange, Defender, Purview, identity systems, and network controls can be correlated during an investigation.

Microsoft’s Zero Trust guidance for Microsoft 365 Copilot reinforces least privilege, identity controls, data governance, and continuous monitoring. These controls reduce risk; none is a universal guarantee against future prompt-injection techniques.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Questions to answer before enabling or expanding Copilot

  • Which repositories can Copilot search, and are external messages included in its context?
  • Can users access confidential documents they do not need for their jobs?
  • Are sensitivity labels and DLP policies applied consistently?
  • Which third-party connectors and agents can call external services?
  • Are outbound requests and AI interactions logged well enough to investigate?
  • How quickly can administrators disable an agent, connector, or workflow?
  • Which users have high-value mailboxes, files, or privileged roles?

Common misunderstandings

“Zero-click” means everyone was compromised

No. It describes the demonstrated interaction requirement. Microsoft reported no evidence of in-the-wild exploitation, and exposure depended on the relevant Copilot processing path, permissions, and data sources.

Copilot bypassed every permission

That is too broad. The danger was manipulating an assistant operating within the user’s accessible context, while overshared data could make that context far larger than intended.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

No customer action means no security work

The server-side fix removed the specific EchoLeak issue. It did not clean up overshared files, classify sensitive data, govern connectors, or detect future indirect prompt injection.

Blocking all external email is the only answer

That can damage business operations. Risk-based filtering, quarantine, labeling, least privilege, controlled connectors, and monitoring are more sustainable defenses.

If suspicious activity is found

  1. Preserve relevant email, Copilot, Defender, Purview, Exchange, identity, and network logs.
  2. Identify affected users, prompts, agents, connectors, and data sources.
  3. Revoke or rotate credentials if external exfiltration is suspected.
  4. Disable the relevant workflow or agent when containment requires it.
  5. Review outbound requests and proxy activity.
  6. Determine whether sensitive data was actually retrieved or merely targeted.
  7. Search for the same malicious content in other users’ mailboxes and repositories.
  8. Contact Microsoft through the tenant’s support or security-response channels.
  9. Correct permission, labeling, DLP, and connector gaps, then document the incident separately from the original CVE.

Why EchoLeak matters beyond Microsoft

Conventional phishing Indirect prompt injection
Targets a human Targets the AI system processing content
Often depends on a click May operate during background retrieval or rendering
Usually seeks credentials, malware execution, or payment May manipulate search, summarization, tool calls, or data handling
Human judgment is the main defense Authorization boundaries, retrieval controls, output handling, and monitoring are central

The same pattern can affect enterprise search assistants, document agents, customer-service bots, and autonomous workflows whenever they read attacker-influenced content, can access private data, or automatically call tools and services. The durable lesson is architectural: instructions and retrieved data need strong separation, and an assistant’s ability to act must be narrower than its ability to read.

EchoLeak was a specific, remediated Microsoft 365 Copilot vulnerability. Its enduring warning is that an AI assistant can amplify an existing permission or governance mistake—and can do so without the traditional phishing click.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.