Why EchoLeak Prompt Injection Is a Legal Risk
EchoLeak (CVE-2025-32711) is a confirmed, server-side-patched prompt-injection vulnerability in Microsoft 365 Copilot with no confirmed in-the-wild exploitation or CISA KEV listing. This record separates the verified exploit facts from the legal exposure for law firms: Rule 1.6 client confidentiality, ABA Formal Opinion 512 duties, and breach-notification assessment.
- Jurisdiction
- United States
- Court
- No court proceeding
- AI tool named
- Microsoft 365 Copilot
- Ruling date
- Jun 11, 2025
- Source document
- View primary court order ↗
- Last verified
- Aug 3, 2026
Lex Machina Review is an independent risk-tracking and reference resource. Nothing on this site is legal advice, and using it does not create an attorney-client relationship. Every record is reviewed against primary sources but may not reflect the most current status of a matter — always verify directly against the cited court order, rule text, or a licensed attorney before relying on it.
Companion explanation — secondary to the source document above
Status: verified vulnerability, patched record, not an active incident
EchoLeak is a real prompt-injection exploit record, and it deserves a place in a law-firm risk file. It does not, on the verified materials, support a statement that law firms were breached through Microsoft 365 Copilot. The narrow status matters: CVE-2025-32711 is a confirmed Microsoft 365 Copilot vulnerability, fixed server-side, with no confirmed in-the-wild exploitation and no CISA Known Exploited Vulnerabilities listing reflected in the NVD record as of August 3, 2026.
NVD describes CVE-2025-32711 as “AI command injection in M365 Copilot” that allows an unauthorized attacker to disclose information over a network, and maps it to CWE-74. The severity record is split in a way risk counsel should preserve: Microsoft’s CNA score is CVSS 9.3, CRITICAL, while NIST’s assessment is CVSS 7.5, HIGH. [1]
The public timeline is also part of the legal record. Aim Labs discovered the issue in January 2025 and privately disclosed it to Microsoft; Microsoft deployed a server-side fix in May 2025; the CVE was published on June 11, 2025; and reporting at disclosure stated that no customer action was required and that there was no evidence of in-the-wild exploitation. [2]
That combination should produce a disciplined entry, not a comfort memo. “Server-side patched” answers the patching question. It does not answer whether a tenant had Copilot enabled, what data Copilot could retrieve for particular lawyers or staff, whether logs were reviewed, or whether any matter-specific confidentiality analysis is needed.
- Verified: CVE-2025-32711 affected Microsoft 365 Copilot and was capable of information disclosure over a network.
- Verified: Microsoft addressed the issue server-side before public disclosure.
- Verified on the cited record: no confirmed exploitation in the wild.
- Not verified by these materials: any particular law firm, client file, privileged communication, or matter workspace was accessed.
- Still assessable by each firm: whether its own Microsoft 365 configuration, Copilot access model, logs, and matter data require further investigation or notification analysis.

The attack chain matters because it follows normal work surfaces
The legal risk in EchoLeak is not that a user carelessly pasted a client memo into a public chatbot. The concern is more ordinary and therefore harder to dismiss: the exploit path used email, retrieval-augmented generation, rendered markdown, automatic fetching behavior, and an allowed Microsoft Teams preview endpoint.
The described chain began with a crafted email. Copilot’s retrieval system could ingest the message, and the malicious instructions could then be surfaced when Copilot answered a later user query. The exploit used reference-style markdown link and image behavior to cause an automatic fetch, then proxied the outbound request through an allow-listed Teams preview API endpoint, asyncgw.teams.microsoft.com/urlp. The published analysis describes this as bypassing Copilot’s cross-prompt-injection classifier, link redaction, and content security policy controls, without requiring the user to click a malicious link. [3][4]

For a firm, the key sentence is not “zero click,” although that phrase explains why the disclosure drew attention. The key sentence is that the exploit could exfiltrate information available to Copilot in the context of an authorized user. That is a bounded technical statement, but the legal consequence is broad: the boundary of the potential exposure is the boundary of what the lawyer, paralegal, assistant, or other Copilot-enabled user could retrieve from email, Teams, SharePoint, and other connected Microsoft 365 locations.
That makes EchoLeak different from a generic warning about prompt injection. It sits inside the same document estate that contains engagement letters, litigation strategy, settlement authority, internal investigations, diligence materials, client board communications, and privileged drafts. If Copilot can reach those materials for a user, then a prompt-injection exfiltration path aimed at Copilot is not merely an AI security curiosity. It is a confidentiality systems problem.
What should be documented before anyone says “breach”
The strongest legal record usually starts by refusing to overclaim. EchoLeak does not prove that a client’s material was exposed. It does justify an assessment of whether client material could have been exposed in a particular tenant, and whether the firm has enough facts to close the file.
A firm’s first memo should separate four questions that are often collapsed in security summaries:
- Was Microsoft 365 Copilot enabled for any lawyers or staff during the relevant period?
- Which repositories, mailboxes, Teams channels, SharePoint sites, and matter workspaces were reachable by those users?
- Did the tenant retain logs or telemetry that could show relevant Copilot activity, message ingestion, or unusual outbound behavior?
- If confidential or privileged material was within scope, what state, contractual, ethical, insurance, or client-guideline notification duties require analysis?
Those questions do not assume notice is required. They preserve the reasoning needed if a client, carrier, regulator, court, or ethics partner later asks how the firm moved from a public CVE to its own conclusion. The difference between “we saw a headline” and “we evaluated exposure” is the difference between a panic response and a defensible record.
The same discipline applies to privilege. A privilege issue is not established by the existence of CVE-2025-32711. But a privilege review may be necessary if a firm determines that privileged matter content was reachable by Copilot and that logs or other evidence suggest exfiltration or unauthorized access. Confidentiality, breach notification, and privilege are related questions; they are not the same question.
Rule 1.6 and ABA Formal Opinion 512 are the better legal frame
For lawyers, EchoLeak should be read through professional responsibility before it is read through sanctions doctrine. ABA Formal Opinion 512, issued July 29, 2024, tells lawyers using generative AI tools to “fully consider their applicable ethical obligations,” including competence, communication, fees, and confidentiality under Rules 1.1, 1.4, 1.5, and 1.6. [5]
That guidance does not say Microsoft 365 Copilot is forbidden, and nothing in the EchoLeak record supports treating Copilot-style systems as categorically unsafe. The better reading is narrower and more practical: when a generative-AI assistant is connected to firm email, chat, and document repositories, the lawyer’s confidentiality analysis must include the tool’s access model, not merely the vendor’s public security posture.
A lawyer who asks Copilot to locate a draft indemnity clause or summarize a Teams thread is not necessarily disclosing material outside the firm. In many deployments, that is exactly why the tool is useful. But the authorized-user model also means that permissions hygiene, matter-site design, external sharing controls, retention, and Copilot eligibility become legal-risk controls. If a lawyer can retrieve a client’s privileged material through Copilot, then a vulnerability that could cause Copilot to disclose retrievable content belongs in the Rule 1.6 file.
For a broader ethics map on generative-AI duties, including ABA Formal Opinion 512 and later state and court developments, see this companion ethics analysis. EchoLeak adds a different layer: it is not about hallucinated citations or lawyer verification of output. It is about whether the assistant’s access to confidential material creates an exfiltration surface that the firm must understand and document.
The “lethal trifecta” is useful if it is kept structural
Kilpatrick Townsend describes prompt-injection exposure through a “lethal trifecta”: standing access to sensitive data, exposure to untrusted content, and an outbound channel. The phrasing is dramatic, but the structure is useful for law firms because it explains why EchoLeak is not confined to prompt wording or user training. [6]

In law-firm terms, the first condition is easy to satisfy. Copilot may have standing access to sensitive data because lawyers and staff have standing access to sensitive data. The second condition is also ordinary: email and chat routinely contain untrusted content from clients, opposing counsel, experts, vendors, courts, recruiters, and unknown senders. The third condition is where EchoLeak becomes concrete, because the exploit analysis describes an outbound path through rendering and an allow-listed Microsoft service rather than through an obvious malicious attachment.
That framing should lead to a permissions and architecture review, not a blanket conclusion that AI assistants are defective. A firm can reduce the first condition by limiting who has Copilot and what repositories are in scope. It can reduce the second by improving how untrusted content is isolated or handled. It can reduce the third by reviewing outbound controls, previews, logging, and allow-list assumptions. The legal question is whether those controls were reasonable for the firm’s matters, clients, jurisdictions, and known risk at the relevant time.
The comparison to other AI incident records is useful only if status labels stay intact. A vendor breach record, for example, raises different notification and due-diligence questions than a patched production vulnerability with no confirmed exploitation. For that distinction, see the Claude breach law-firm liability record. EchoLeak is not that kind of record on the present materials.
Breach notification is an assessment duty here
A public CVE does not itself start every notification clock. Nor does a vendor’s server-side fix close every notification analysis. The right position for EchoLeak is between those extremes: a firm that deployed Microsoft 365 Copilot should decide whether the vulnerability intersected with client material, personal information, protected health information, trade secrets, or contractually protected data in that firm’s environment.
That assessment should be jurisdiction-specific. State breach-notification statutes, client outside-counsel guidelines, cyber-insurance provisions, protective orders, business associate agreements, and international rules may define reportable events differently. Some turn on unauthorized acquisition; some turn on access; some turn on risk of harm; some require regulator notice only after particular thresholds or subject-matter triggers are met. EchoLeak supplies a verified technical path. It does not supply the tenant facts needed to apply those rules.
The most useful legal file will therefore record both the absence and the presence of facts: no confirmed in-the-wild exploitation in the public record; no client-specific exposure established by the CVE alone; whether Copilot was enabled; which custodians and matter repositories were in scope; what logs were available; what the firm could and could not determine; and who approved the closure or escalation decision.
Related developments are a risk horizon, not proof of EchoLeak liability
Prompt-injection law is developing faster in commentary than in binding decisions. That is a poor reason to ignore it and an equally poor reason to overstate it.
The reported Brazil TRT-8 Galileu matter is notable because it has been described as a judicial sanction involving prompt injection, including a reported R$84,000 fine in a May 12, 2026 ruling. The primary order was not directly retrieved in the cited sources, and the matter is non-U.S. and non-binding for U.S. firms. It should be treated as a cautionary development about courts encountering prompt manipulation, not as a sanctions precedent for EchoLeak or for Microsoft 365 Copilot use. [7][8]
The OpenEvidence disputes are similarly important but unsettled. As described in law-firm analysis, the pleadings raise prompt-injection and trade-secret theories, but they do not yet establish a merits rule that prompt injection is improper means under the Defend Trade Secrets Act. Pleadings can show where arguments are going; they are not holdings. [6]
Adjacent technical research on GitHub Copilot and Cursor, including CVE-2025-53773 weaponization research, points in the same general direction: agentic coding and productivity tools are becoming a broader prompt-injection risk class. That does not make the EchoLeak facts bigger than they are. It does make them harder for legal departments to file under “one-off AI bug” and forget. [9]
The classification that should survive review
EchoLeak is not proof that any law firm was breached. It is not a prompt-injection sanctions precedent. It is not a reason to describe Microsoft 365 Copilot as categorically unsafe. It is a verified production-system exfiltration path in a tool that many legal organizations use precisely because it can retrieve internal work product.
That is enough to make it legal risk. The protected material available to Copilot may be the same material lawyers have independent duties to protect: client confidences, privileged communications, trade secrets, personal information, litigation strategy, and regulated data. A patched vulnerability can still require a written assessment, especially when the architecture had access to material that would matter if it left the tenant.
The defensible firm record is therefore modest but complete: confirmed vulnerability, server-side patched, no confirmed exploitation, no KEV listing as of August 3, 2026, tenant-specific exposure assessment required if Copilot had access to confidential or privileged matter material.
References
- NVD CVE-2025-32711 Detail — National Vulnerability Database, June 11, 2025.
- Zero-Click AI Vulnerability Exposes Microsoft 365 Copilot Data Without User Interaction — The Hacker News, June 12, 2025.
- EchoLeak: The First Real-World Zero-Click Prompt Injection Exploit in a Production LLM System — arXiv.
- Preventing Zero-Click AI Threats: Insights from EchoLeak — Trend Micro Research, July 15, 2025.
- ABA issues first ethics guidance on a lawyer’s use of AI tools — American Bar Association, July 29, 2024.
- Prompt Injection Hacking: Emerging Trade Secret, Employment, and Litigation Risks — Kilpatrick Townsend & Stockton LLP, July 24, 2026.
- Lawyers Fined for Trying to Fool a Court’s AI with Prompt Injection — JLE blog.
- OECD AI Incident Database incident 1497 — OECD AI Incident Database.
- New Vulnerability in GitHub Copilot and Cursor — Pillar Security.
Related records
Tool profile
Browse tool evaluations →Governing regulation
Browse the obligations tracker →Preventive workflow
Browse verification workflows →
Report a correction or tip
Spotted an outdated figure, a misstated fact, or a ruling this case record should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.
Report a correction or tip for this record →