agent-postmortems a structured database of real AI-agent failures

← all incidents

hazard critical confidence: confirmed status: final

EchoLeak: zero-click prompt injection could exfiltrate Microsoft 365 Copilot context

2025-echoleak-m365-copilot · 2025-06-11

A crafted email carrying a hidden prompt (CVE-2025-32711, CVSS 9.3) could be retrieved by Microsoft 365 Copilot during a later unrelated query and silently exfiltrate context with no user click. Disclosed by Aim Security and fixed server-side; Microsoft reported no evidence of exploitation in the wild.

System

Framework
Microsoft 365 Copilot (RAG assistant)
Tools
email, sharepoint, onedrive, teams
Vendor
Microsoft
Autonomy
human-in-the-loop

Classification

Primary class
prompt-injection
Chain
prompt-injection/indirect → memory-context-poisoning/rag-poisoning → data-exfiltration/via-output
Attack vector
untrusted-content
Causation
entity: human · intentionality: intentional · timing: post-deployment

Trigger

A crafted email containing a hidden prompt payload (e.g. white-on-white text or an HTML comment) was retained by Copilot. When the user later asked Copilot a normal question, the RAG engine retrieved the email and executed the hidden instructions, exfiltrating context without any user click.

Root cause

Untrusted external content entered the model's trust boundary and was acted on as instructions, chaining multiple bypasses (XPIA classifier evasion, reference-style Markdown link redaction bypass, auto-fetched images, a Teams proxy allowed by the content security policy).

Contributing factors

  • Inbound email was retrievable by the assistant without provenance separation.
  • Auto-fetched images and an allowlisted proxy provided an exfiltration channel.
  • The prompt-injection classifier could be evaded by phrasing aimed at the user, not the model.

Detection

Discovered and disclosed by Aim Security researchers, who named it "EchoLeak" (CVE-2025-32711).

Recovery

Microsoft addressed the vulnerability server-side; the fix required no customer action.

Prevention

Enforce strict separation between untrusted retrieved content and instructions; harden prompt-injection classifiers; restrict outbound link/image fetching and CSP-allowed proxies; scope what an assistant may return externally.

Blast radius

Data
Any data reachable in Copilot's context (emails, Teams messages, OneDrive, SharePoint, Office files) could be silently exfiltrated. Rated CVSS 9.3 (critical). confidential
User harm
Potential confidential-data exposure for organisations; Microsoft reported no evidence of malicious exploitation in the wild. none-reported
Scope
any M365 Copilot tenant prior to the server-side fix
Reversibility
irreversible

References

OWASP LLM
LLM01 LLM02 LLM04
MITRE ATLAS
AML.T0024 AML.T0051
Tags
zero-click rag copilot

Sources

Cite this incident

@misc{2025-echoleak-m365-copilot,
  title = {EchoLeak: zero-click prompt injection could exfiltrate Microsoft 365 Copilot context},
  year = {2025},
  howpublished = {agent-postmortems},
  url = {https://swarmproof.github.io/agent-postmortems/2025-echoleak-m365-copilot/}
}