{"id":4590,"date":"2025-06-12T10:03:58","date_gmt":"2025-06-12T10:03:58","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/06\/12\/0-click-microsoft-365-copilot-vulnerability-let-attackers-exfiltrates-sensitive-data-abusing-teams\/"},"modified":"2025-06-12T10:03:58","modified_gmt":"2025-06-12T10:03:58","slug":"0-click-microsoft-365-copilot-vulnerability-let-attackers-exfiltrates-sensitive-data-abusing-teams","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/06\/12\/0-click-microsoft-365-copilot-vulnerability-let-attackers-exfiltrates-sensitive-data-abusing-teams\/","title":{"rendered":"0-Click Microsoft 365 Copilot Vulnerability Let Attackers Exfiltrates Sensitive Data Abusing Teams"},"content":{"rendered":"<p>    0-Click Microsoft 365 Copilot Vulnerability Let Attackers Exfiltrates Sensitive Data Abusing Teams<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A critical zero-click vulnerability in Microsoft 365 Copilot, dubbed \u201cEchoLeak,\u201d enables attackers to automatically exfiltrate sensitive organizational data without requiring any user interaction.<\/p>\n<p>The vulnerability represents a significant breakthrough in AI security research, introducing a new class of attack called \u201cLLM Scope Violation\u201d that could affect other AI-powered applications beyond Microsoft\u2019s platform.<\/p>\n<p>The EchoLeak attack exploits fundamental design flaws in how <a href=\"https:\/\/cybersecuritynews.com\/m365-copilot-chat-safelinks\/\" target=\"_blank\" rel=\"noreferrer noopener\">M365 Copilot<\/a> processes and retrieves information from organizational data stores.<\/p>\n<p>The vulnerability enables external attackers to send specially crafted emails that bypass multiple security layers, allowing them to extract the most sensitive information from a victim\u2019s Microsoft Graph data, including emails, <a href=\"https:\/\/cybersecuritynews.com\/microsoft-onedrive-default-sync\/\" target=\"_blank\" rel=\"noreferrer noopener\">OneDrive files<\/a>, SharePoint documents, and Teams conversations.<\/p>\n<p>What makes this attack particularly dangerous is its zero-click nature. Unlike traditional cyberattacks that require users to click on malicious links or download infected files, EchoLeak operates entirely in the background.<\/p>\n<p>An attacker simply needs to send an email to a target within an organization, and the vulnerability can be triggered when the victim interacts with M365 Copilot for any routine business task.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg4r2u_jY7G8c51XvCpUrGjDixQQVcbyp5Mbf-QrW0xW0rxW-SptO0hbFQs8k7mxAmi2Gicxs8pcbktduMa7womCCQvThjDYRmSsP6L24B1-kDdcn7Yhf4h789n_BKeHlXBNF7ooY67iNfGpb95kdEtj9fVeWQ6AbFg0FWdBPmdXr1tc8JrxXdtTSf1Pht2\/s16000\/EchoLeak%25201.webp?ssl=1\" alt=\"Zero-Click Microsoft 365 Copilot Vulnerability\"><figcaption class=\"wp-element-caption\">Zero-Click Microsoft 365 Copilot Vulnerability (<em>Source: Aim Labs<\/em>)<\/figcaption><\/figure>\n<h2 class=\"wp-block-heading\" id=\"technical-sophistication\"><strong>Zero-Click Microsoft 365 Copilot Vulnerability<\/strong><\/h2>\n<p>The attack chain demonstrates remarkable technical sophistication, successfully bypassing four critical security measures that Microsoft has implemented as best practices.<\/p>\n<p>First, it circumvents XPIA (cross-prompt injection attack) classifiers by phrasing malicious instructions as if they were intended for human recipients rather than AI systems.<\/p>\n<p>The researchers <a href=\"https:\/\/www.aim.security\/lp\/aim-labs-echoleak-blogpost\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">also discovered<\/a> multiple bypasses for Microsoft\u2019s link redaction mechanisms, exploiting lesser-known markdown formatting variations that aren\u2019t recognized by the security filters. These include reference-style markdown links and images that slip past the content scanning systems.<\/p>\n<p>Perhaps most concerning is the Content Security Policy (CSP) bypass that enables automatic data exfiltration. The researchers identified specific <a href=\"https:\/\/cybersecuritynews.com\/microsoft-teams-update-productivity\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Teams<\/a> and SharePoint endpoints that can forward requests to external servers while remaining within the allowed domain whitelist, creating an invisible channel for sensitive data to leave the organization.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg_rV98SgQ8o0T8ZC2dyiXWLqILxCCfOC5G6p-lufcqk3Y454NvOpg-dZEX7l5Ku3V-DBnKA6RyZ10VlJfx_YgnvMABgCh-0qjF5LhiEnApbsyHkPvT1JA5bisDiaVz-W2oKTzFl4yIFIa7Eu127PTbzsaZjyQENgYKal-xItReyWT93Xw9JCL5aGA8tpca\/s16000\/EchoLeak%2520copilot.webp?ssl=1\" alt=\"Zero-Click Microsoft 365 Copilot Vulnerability\"><figcaption class=\"wp-element-caption\">Zero-Click Microsoft 365 Copilot Vulnerability Data Exfiltration (<em>Source: Aim Labs<\/em>)<\/figcaption><\/figure>\n<\/div>\n<p>Aim Labs has introduced the term \u201cLLM Scope Violation\u201d to describe the core vulnerability mechanism. This occurs when an attacker\u2019s instructions embedded in untrusted content successfully direct the AI system to access and process privileged organizational data without explicit user consent.<\/p>\n<p>The researchers argue this represents a violation of the Principle of Least Privilege, where low-privilege external content gains unauthorized access to high-privilege internal information through the AI intermediary.<\/p>\n<p>The discovery highlights growing security challenges as organizations increasingly adopt AI-powered productivity tools. M365 Copilot\u2019s integration with Microsoft Graph gives it extensive access to organizational data, making it an attractive target for sophisticated attacks.<\/p>\n<p>Microsoft\u2019s MSRC team has been notified of the vulnerability, though specific details about patches or mitigations have not been disclosed. Aim Labs reports that no customers are known to have been impacted by this vulnerability to date.<\/p>\n<p>This research represents a significant advancement in understanding how threat actors can exploit AI agents by leveraging their internal mechanics. As organizations continue deploying <a href=\"https:\/\/cybersecuritynews.com\/ai-powered-tools-are-detecting-and-preventing-cyber-threats\/\" target=\"_blank\" rel=\"noreferrer noopener\">AI-powered tools<\/a>, the EchoLeak discovery underscores the need for more sophisticated security frameworks specifically designed for AI applications.<\/p>\n<p>The vulnerability\u2019s zero-click nature and potential for data exfiltration make it particularly suited for corporate espionage and extortion campaigns, highlighting the evolving threat landscape in our increasingly AI-integrated business environment.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Live Credential Theft Attack Unmask &amp; Instant Defense \u2013 <a href=\"https:\/\/webinars.indusface.com\/credential-abuse-unmasked-live-attack-and-instant-defense\/register?utm_source=gbhackers-blog-cta&amp;utm_campaign=2025-jun-attack-simulation&amp;utm_medium=referral\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Free Webinar<\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/zero-click-microsoft-365-copilot-vulnerability\/\">0-Click Microsoft 365 Copilot Vulnerability Let Attackers Exfiltrates Sensitive Data Abusing Teams<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/zero-click-microsoft-365-copilot-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>0-Click Microsoft 365 Copilot Vulnerability Let Attackers Exfiltrates Sensitive Data Abusing Teams A critical zero-click vulnerability in Microsoft 365 Copilot, dubbed \u201cEchoLeak,\u201d enables attackers to automatically exfiltrate sensitive organizational data without requiring any user interaction. The vulnerability represents a significant breakthrough in AI security research, introducing a new class of attack called \u201cLLM Scope Violation\u201d [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63],"tags":[130],"class_list":["post-4590","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4590"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=4590"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4590\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=4590"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=4590"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=4590"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}