Zero-Click AI Vulnerability Exposes Microsoft 365 Copilot Data Without User Interaction

Post Reply
Shane1145
Posts: 1836
Joined: Wed Sep 25, 2024 2:31 pm

Zero-Click AI Vulnerability Exposes Microsoft 365 Copilot Data Without User Interaction

Post by Shane1145 »

A novel attack technique named EchoLeak has been characterized as a "zero-click" artificial intelligence (AI) vulnerability that allows bad actors to exfiltrate sensitive data from Microsoft 365 (M365) Copilot's context sans any user interaction.

The critical-rated vulnerability has been assigned the CVE identifier CVE-2025-32711 (CVSS score: 9.3). It requires no customer action and has been already addressed by Microsoft. There is no evidence that the shortcoming was exploited maliciously in the wild.

https://thehackernews.com/2025/06/zero- ... poses.html
Post Reply