Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CVE-2025-32711 describes an information-disclosure vulnerability in Microsoft 365 Copilot. The reported EchoLeak attack chain used attacker-controlled external content to influence Copilot, then relied on how a response referenced remote content and how that content could be fetched to transmit information. The research paper reports that Microsoft deployed a server-side fix in May 2025; it is not, by itself, current operational guidance from Microsoft.

What is CVE-2025-32711?

The National Vulnerability Database (NVD) describes CVE-2025-32711 as “Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.” NVD identifies Microsoft 365 Copilot as the affected product and maps the weakness to CWE-74, improper neutralization of special elements in output used by a downstream component.

NVD published the record on June 11, 2025, and last modified it on June 17, 2026. The CVE concerns information disclosure; the record does not establish that every prompt injection, or every use of Copilot, exposes data.

How did the reported EchoLeak attack work?

In their paper, “EchoLeak: The First Real-World Zero-Click Prompt Injection Exploit in a Production LLM System”, Pavan Reddy and Aditya Sanjay Gujral describe a chain with several linked stages:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. External content enters the assistant’s context. The content is controlled by an attacker and crafted to influence Copilot’s response. The risk is that untrusted text may be treated as instructions, rather than merely as data to analyze.
  2. The response carries information in a reference. The paper describes sensitive information being encoded into a link or image reference in Copilot’s output.
  3. A fetch or preview path transmits the reference. Automatic resource fetching, including a Microsoft Teams preview route described by the authors, can cause the referenced resource to be requested and disclose the encoded information over a network.

The important point is the interaction between untrusted input, the assistant’s output, and downstream rendering or fetching behavior. Prompt injection alone does not automatically mean data theft; the reported disclosure depended on this particular chain.

What is established about the fix?

The technical paper reports that Microsoft deployed a server-side fix in May 2025, before the paper and public disclosure appeared on June 11, 2025. That timing is the paper’s account of remediation, not a current statement of service status or a Microsoft troubleshooting instruction.

Microsoft has an official Security Response Center advisory for CVE-2025-32711. The available advisory material does not establish specific current steps, affected configurations, or whether an administrator needs to take action. For operational decisions, consult the live advisory and Microsoft guidance for your tenant; do not infer a required patch or configuration change from the paper alone.

What does the paper prove—and not prove?

The authors characterize their work as analysis of already-public information. They state: “This work is a case study of EchoLeak based solely on analysis of already-public data; we did not reproduce the attack or run any experiments.” They also say they did not comprehensively evaluate practical mitigations. Accordingly, the paper documents a reported vulnerability and attack chain; it is not an independent reproduction, a product comparison, or evidence that a particular defense is sufficient.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What defenses does the paper recommend?

The authors discuss engineering approaches that address different links in the chain. These are recommendations, not controls whose effectiveness the paper tested comparatively:

  • Separate trusted and untrusted content: preserve the distinction between system instructions and external material supplied for analysis.
  • Use provenance-aware access controls: account for where content came from when determining what information an assistant can access or act on.
  • Validate output: inspect or constrain generated references and other output that a downstream component may interpret.
  • Restrict content and network egress: use content security policy and egress controls to limit unintended requests to external resources.
  • Continue adversarial testing: evaluate interactions among prompts, generated output, previews, and fetching components rather than assessing the model in isolation.

These measures address trust boundaries, output handling, and network behavior. The paper does not establish that any one measure—or this list by itself—prevents all prompt-injection attacks.

Key dates

Event Date and qualification
Reported server-side fix May 2025, as reported by the EchoLeak paper.
NVD publication and public disclosure June 11, 2025; the NVD record was published on this date, and the paper reports public disclosure then.
EchoLeak paper September 6, 2025, the date given for the paper.
NVD record last modified June 17, 2026.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.