Recommended Free Tools
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
EchoLeak was a real vulnerability in Microsoft 365 Copilot, not merely a prompt-injection thought experiment. Tracked as CVE-2025-32711, it allowed a specially crafted message to manipulate Copilot into retrieving information available in a victim’s Microsoft 365 context and sending it toward attacker-controlled infrastructure without the victim opening the message or clicking a link. Microsoft says it deployed a server-side fix in May 2025, found no evidence of exploitation in the wild, and required no customer action for this specific vulnerability. The broader risk—untrusted content being interpreted as instructions by an AI assistant with access to business data—remains.
The essential facts
| Item | What is established |
|---|---|
| Name | EchoLeak, a name used by Aim Security |
| Identifier | CVE-2025-32711 |
| Affected service | Microsoft 365 Copilot, not every Microsoft product branded “Copilot” |
| Reported to Microsoft | January 2025, according to the AAAI case study |
| Server-side remediation | Deployed before public disclosure, reportedly in May 2025 |
| Public disclosure | June 11, 2025 |
| User interaction in the demonstration | No opening, clicking, or deliberate Copilot interaction was required |
| Exploitation status | Microsoft said it found no evidence of in-the-wild exploitation |
| Customer action for this CVE | Microsoft said no customer action was required |
“First zero-click AI exploit” should be read narrowly. Aim Security and later technical analyses describe EchoLeak as the first publicly documented zero-click prompt-injection vulnerability demonstrated against a production large-language-model application—not the first AI vulnerability or the first zero-click attack of any kind.
Sources: Aim Security, AAAI paper, and Microsoft’s MSRC advisory.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWhat EchoLeak was
EchoLeak was an indirect prompt-injection and information-disclosure flaw. The attacker did not need to compromise a Microsoft 365 server or install malware. Instead, attacker-controlled instructions were hidden in content that Copilot was expected to read as data, such as an email.
#1 Best Overall
That distinction matters. Microsoft 365 Copilot can ground responses in information the signed-in user is authorized to access across services such as Outlook, OneDrive, SharePoint, Office files, and Teams, subject to tenant configuration and indexing. EchoLeak abused the boundary between that retrieved content and the instructions governing the model.
How the zero-click attack chain worked
The public material describes a working proof of concept. The following is a conceptual explanation, not a reusable exploit payload.
- Crafted content arrives. An attacker sends specially constructed email or other content that the relevant Copilot workflow can retrieve or process.
- Instructions are mixed with ordinary text. The malicious text is designed to influence the model while appearing to be part of the material it is reading.
- Copilot adds the content to its working context. The model processes the attacker’s text alongside the user’s legitimate request and permitted Microsoft 365 sources.
- The injected instructions redirect the task. Rather than only summarizing or answering, Copilot is induced to search for information in the user’s accessible context.
- Extracted data is put into an automatically fetched resource. The demonstration used an image or similar external resource whose URL could carry the extracted content.
- A Microsoft-hosted proxy or preview path helps the request reach outside systems. Aim Security and the AAAI paper describe abuse of an allowed Microsoft domain and a Teams asynchronous preview mechanism to proxy the request.
- Data leaves without a victim click. Automatic processing and fetching complete the chain, which is why the researchers called it zero-click.
The relevant pipeline still had to process the content. “Zero-click” does not mean every tenant was continuously exposed; it means the demonstrated victim did not have to open the message or knowingly invoke Copilot for the chain to operate.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteWhat information could be targeted?
The practical scope was bounded by the victim’s identity, permissions, connected repositories, indexing, labels, and tenant settings. It was not an automatic read of every file in every Microsoft 365 tenant.
- Outlook mail and attachments
- OneDrive files and Office documents
- SharePoint pages and documents
- Microsoft Teams conversations and shared files
- Other Microsoft Graph-connected work data available to the Copilot context
A useful distinction is between data Copilot could reach under the user’s permissions and data researchers demonstrated extracting in the proof of concept. EchoLeak did not necessarily bypass ordinary authorization. It could make an assistant collect and transmit information that the user could already access—potentially turning existing oversharing into a much faster discovery and exfiltration path.
Why existing defenses were insufficient
The case exposed a confused trust boundary: the application treated retrieved material as untrusted data, while the model could interpret text inside that material as instructions. Aim Security and the AAAI analysis describe a chain that could evade or work around several expected safeguards:
- Cross-prompt-injection classifiers
- External-link redaction
- Content Security Policy restrictions
- Copilot reference and citation behavior
- Assumptions that retrieved text remains passive data
Filtering at the model layer is therefore only one control. A system can reject obvious “ignore previous instructions” text yet still be influenced by obfuscated, contextual, or novel instructions embedded in a document or email. Protection has to span ingestion, retrieval, authorization, rendering, outbound networking, and monitoring.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Microsoft’s current Defender for Office 365 prompt-injection guidance specifically addresses concealed email content such as white-on-white text, zero-size text, off-screen elements, and HTML/CSS tricks intended for an AI system rather than a human reader.
Rank #3
What Microsoft fixed—and what it did not claim
Microsoft’s MSRC entry says the remediation was server-side and that no customer action was required for CVE-2025-32711. That means customers should not search for a nonexistent EchoLeak installer or CVE-specific command.
Microsoft also stated that it had found no evidence of exploitation in the wild. Aim Security demonstrated exploitability; that is different from proving that criminals used the technique against customers. “Could exfiltrate data” and “did exfiltrate customer data” are not interchangeable claims.
Fixing the specific vulnerability does not eliminate indirect prompt injection as a class. Microsoft 365 Copilot is a cloud service, and the incident does not automatically apply to consumer Microsoft Copilot, Security Copilot, GitHub Copilot, Copilot Studio agents, or third-party assistants.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
What Microsoft 365 administrators should do now
No emergency patch is required for the fixed CVE, but organizations expanding or operating Copilot should treat this as a data-governance and trust-boundary issue.
Rank #4
- Confirm service status. Review Microsoft 365 service health and security communications, and verify that no legacy or disconnected Copilot integration remains in use.
- Harden the inbox. Review Defender for Office 365 prompt-injection protections, quarantine policies, Safe Links, and investigation workflows.
- Find oversharing. Audit SharePoint, OneDrive, Teams, and Exchange permissions; remove stale access and unnecessary external sharing.
- Classify sensitive information. Use Microsoft Purview sensitivity labels, DLP, data-security-posture tools, insider-risk workflows, and audit features as appropriate. Microsoft’s Copilot security guidance explains the available controls.
- Govern agents and connectors. Record which agents, plugins, third-party connectors, and external services can retrieve data or take actions. Define who can enable or disable them.
- Monitor egress and identity activity. Alert on unusual outbound requests, anomalous mailbox or file access, suspicious proxy use, and unexpected AI-generated activity.
- Test response procedures. Ensure logs from Copilot, Exchange, Defender, Purview, identity systems, and network controls can be correlated during an investigation.
Microsoft’s Zero Trust guidance for Microsoft 365 Copilot reinforces least privilege, identity controls, data governance, and continuous monitoring. These controls reduce risk; none is a universal guarantee against future prompt-injection techniques.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Questions to answer before enabling or expanding Copilot
- Which repositories can Copilot search, and are external messages included in its context?
- Can users access confidential documents they do not need for their jobs?
- Are sensitivity labels and DLP policies applied consistently?
- Which third-party connectors and agents can call external services?
- Are outbound requests and AI interactions logged well enough to investigate?
- How quickly can administrators disable an agent, connector, or workflow?
- Which users have high-value mailboxes, files, or privileged roles?
Common misunderstandings
“Zero-click” means everyone was compromised
No. It describes the demonstrated interaction requirement. Microsoft reported no evidence of in-the-wild exploitation, and exposure depended on the relevant Copilot processing path, permissions, and data sources.
Copilot bypassed every permission
That is too broad. The danger was manipulating an assistant operating within the user’s accessible context, while overshared data could make that context far larger than intended.
No customer action means no security work
The server-side fix removed the specific EchoLeak issue. It did not clean up overshared files, classify sensitive data, govern connectors, or detect future indirect prompt injection.
Best Value
Blocking all external email is the only answer
That can damage business operations. Risk-based filtering, quarantine, labeling, least privilege, controlled connectors, and monitoring are more sustainable defenses.
If suspicious activity is found
- Preserve relevant email, Copilot, Defender, Purview, Exchange, identity, and network logs.
- Identify affected users, prompts, agents, connectors, and data sources.
- Revoke or rotate credentials if external exfiltration is suspected.
- Disable the relevant workflow or agent when containment requires it.
- Review outbound requests and proxy activity.
- Determine whether sensitive data was actually retrieved or merely targeted.
- Search for the same malicious content in other users’ mailboxes and repositories.
- Contact Microsoft through the tenant’s support or security-response channels.
- Correct permission, labeling, DLP, and connector gaps, then document the incident separately from the original CVE.
Why EchoLeak matters beyond Microsoft
| Conventional phishing | Indirect prompt injection |
|---|---|
| Targets a human | Targets the AI system processing content |
| Often depends on a click | May operate during background retrieval or rendering |
| Usually seeks credentials, malware execution, or payment | May manipulate search, summarization, tool calls, or data handling |
| Human judgment is the main defense | Authorization boundaries, retrieval controls, output handling, and monitoring are central |
The same pattern can affect enterprise search assistants, document agents, customer-service bots, and autonomous workflows whenever they read attacker-influenced content, can access private data, or automatically call tools and services. The durable lesson is architectural: instructions and retrieved data need strong separation, and an assistant’s ability to act must be narrower than its ability to read.
EchoLeak was a specific, remediated Microsoft 365 Copilot vulnerability. Its enduring warning is that an AI assistant can amplify an existing permission or governance mistake—and can do so without the traditional phishing click.
Free tools Windows power users keep installed
One-click scans. No signup required.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

