Skip to content
Registry/Agents/Microsoft 365 Copilot
Agent Profile

Microsoft 365 Copilot

Microsoft

Microsoft's AI assistant embedded across Microsoft 365 apps, with access to Outlook, OneDrive, SharePoint and Teams content.

2
Cases
4.0/5
Severity
0
APM-0080Microsoft 365 Copilot4SEVERE
Jun 15, 2026

SearchLeak let a single click on a malicious link pull emails, files and MFA codes out of Microsoft 365 Copilot

Varonis Threat Labs disclosed CVE-2026-42824, a critical flaw in Microsoft 365 Copilot Enterprise Search. Clicking a single crafted link chained three bugs: injection of the URL parameter into the prompt, a rendering race condition, and abuse of Content Security Policy allowlisting to exfiltrate data through Bing's infrastructure. The attack could reach emails and calendar details, indexed SharePoint and OneDrive files, one-time and MFA codes, password-reset links, meeting notes and salary data. Because Copilot Enterprise is a managed service, tenant admins could not patch it themselves; Microsoft mitigated the flaw on its backend.

0
APM-0071Microsoft 365 Copilot4SEVERE
Jun 11, 2025

'EchoLeak' was the first zero-click attack on an AI agent: a single email could make Microsoft 365 Copilot leak company data

Disclosed in June 2025, EchoLeak (CVE-2025-32711, CVSS 9.3) let an attacker exfiltrate data from Microsoft 365 Copilot with no user action. A benign-looking email carried a hidden prompt injection, and Copilot's default behavior of combining trusted and untrusted content ('LLM scope violation') caused it to leak accessible data such as chat logs, OneDrive files, SharePoint and Teams content. Microsoft patched it; researchers at Aim Labs found no in-the-wild exploitation.