EchoLeak: zero-click prompt injection could exfiltrate Microsoft 365 Copilot context
2025-echoleak-m365-copilot · 2025-06-11
A crafted email carrying a hidden prompt (CVE-2025-32711, CVSS 9.3) could be retrieved by Microsoft 365 Copilot during a later unrelated query and silently exfiltrate context with no user click. Disclosed by Aim Security and fixed server-side; Microsoft reported no evidence of exploitation in the wild.
System
- Framework
- Microsoft 365 Copilot (RAG assistant)
- Tools
- email, sharepoint, onedrive, teams
- Vendor
- Microsoft
- Autonomy
- human-in-the-loop
Classification
- Primary class
- prompt-injection
- Chain
- prompt-injection/indirect → memory-context-poisoning/rag-poisoning → data-exfiltration/via-output
- Attack vector
- untrusted-content
- Causation
- entity: human · intentionality: intentional · timing: post-deployment
Trigger
A crafted email containing a hidden prompt payload (e.g. white-on-white text or an HTML comment) was retained by Copilot. When the user later asked Copilot a normal question, the RAG engine retrieved the email and executed the hidden instructions, exfiltrating context without any user click.
Root cause
Untrusted external content entered the model's trust boundary and was acted on as instructions, chaining multiple bypasses (XPIA classifier evasion, reference-style Markdown link redaction bypass, auto-fetched images, a Teams proxy allowed by the content security policy).
Contributing factors
- Inbound email was retrievable by the assistant without provenance separation.
- Auto-fetched images and an allowlisted proxy provided an exfiltration channel.
- The prompt-injection classifier could be evaded by phrasing aimed at the user, not the model.
Detection
Discovered and disclosed by Aim Security researchers, who named it "EchoLeak" (CVE-2025-32711).
Recovery
Microsoft addressed the vulnerability server-side; the fix required no customer action.
Prevention
Enforce strict separation between untrusted retrieved content and instructions; harden prompt-injection classifiers; restrict outbound link/image fetching and CSP-allowed proxies; scope what an assistant may return externally.
Blast radius
- Data
- Any data reachable in Copilot's context (emails, Teams messages, OneDrive, SharePoint, Office files) could be silently exfiltrated. Rated CVSS 9.3 (critical). confidential
- User harm
- Potential confidential-data exposure for organisations; Microsoft reported no evidence of malicious exploitation in the wild. none-reported
- Scope
- any M365 Copilot tenant prior to the server-side fix
- Reversibility
- irreversible
References
- OWASP LLM
- LLM01 LLM02 LLM04
- MITRE ATLAS
- AML.T0024 AML.T0051
- Tags
- zero-click rag copilot
Sources
Cite this incident
Permalink: https://swarmproof.github.io/agent-postmortems/2025-echoleak-m365-copilot/
@misc{2025-echoleak-m365-copilot,
title = {EchoLeak: zero-click prompt injection could exfiltrate Microsoft 365 Copilot context},
year = {2025},
howpublished = {agent-postmortems},
url = {https://swarmproof.github.io/agent-postmortems/2025-echoleak-m365-copilot/}
}