Researchers Detail Zero-Click Copilot Exploit 'EchoLeak'
ID: 4bda6619-1e88-5351-a893-351c336eef16
STIX ID: report--4bda6619-1e88-5351-a893-351c336eef16
Feed Name: Dark Reading
Threat Score
Date Published: 2025-06-12
Date Updated: 2026-04-21
Author: Alexander Culafi, Senior News Writer, Dark Reading
...
...
Aim Security disclosed EchoLeak (CVE-2025-32711), a critical zero-click prompt-injection vulnerability in Microsoft 365 Copilot that could allow attackers to craft emails and use reference-style markdown links to exfiltrate sensitive Copilot context to attacker-controlled domains; Microsoft has patched the issue, assigned a CVSS of 9.3, and reports no known customer impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
