A security researcher discovered a vulnerability in Microsoft 365 Copilot that allowed users to access and summarize files without triggering audit log entries. This flaw could be exploited by malicious insiders to exfiltrate data undetected, posing significant risks to organizations requiring strict compliance and security logging. Microsoft fixed the issue in August 2025 but declined to issue a CVE or notify customers, citing the vulnerability's 'important' classification.
A vulnerability in Microsoft 365 Copilot reportedly allowed users to access and summarize files without generating audit log entries, allegedly undermining traceability and compliance. Security researcher Zack Korman disclosed the issue to Microsoft, which reportedly classified it as "important" and fixed it on August 17, 2025, but reportedly chose not to notify customers or assign a CVE.
Risk classification
- Primary risk domain: 2 Privacy & Security
- Primary risk subdomain: 2.2 AI system security vulnerabilities and attacks
The incident involves a security vulnerability in Microsoft 365 Copilot that allowed users to bypass audit logging, creating a significant security flaw that could be exploited for unauthorized data access.
Causal factors
- Entity: AI
- Intent: Unintentional
- Timing: Post-deployment
The risk stems from an unintentional security vulnerability in the deployed Microsoft 365 Copilot system, where specific user prompts caused the AI to bypass standard audit logging.
EU AI Act risk tier
- Risk tier: 3 Limited Risk
Risk Level 3: Limited Risk. The system is a general-purpose AI assistant/chatbot, which is subject to transparency obligations under the EU AI Act.
AI system and alleged parties
- AI system: Microsoft 365 Copilot (Microsoft)
- AI purpose: Chatbot; Writing Assistant
- Behaviour type: Assistant
- Alleged developer: Microsoft
- Alleged deployer: Microsoft
- Alleged harmed parties: Organizations relying on audit logs for compliance and security, Microsoft 365 Copilot enterprise customers
Harm severity
Highest direct severity in any category: Negligible. Severity is scored from Negligible to Catastrophic in each harm category, for harm the reports describe as caused directly or indirectly by the AI system.
- Physical: direct Negligible, indirect Negligible
- Infrastructure: direct Negligible, indirect Negligible
- Property: direct Negligible, indirect Negligible
- Financial: direct Negligible, indirect Negligible
- Environmental: direct Negligible, indirect Negligible
- Malicious content: direct Negligible, indirect Negligible
- Differential treatment: direct Negligible, indirect Negligible
- Civil rights: direct Negligible, indirect Negligible
- Democracy: direct Negligible, indirect Negligible
- Privacy: direct Negligible, indirect Negligible
- Psychological: direct Negligible, indirect Negligible
- Epistemic: direct Negligible, indirect Negligible
- Child sexual exploitation and abuse: direct Negligible, indirect Negligible
People affected
Potential causes
Management
- Failure to Address Prior Report: Zenity CTO reported the issue a year prior, but management did not fix it.
- Non-Disclosure Decision: Management chose not to notify customers or publicize the vulnerability.
- Downplaying Vulnerability Severity: Classifying the issue as 'important' rather than 'critical' to avoid CVE.
Technology
- Prompt Instructions Bypass Logs: Asking Copilot to omit links resulted in no audit log entry being recorded.
- Truncation of Chat History: Copilot truncates chats, making historical verification of bypasses difficult.
Data Inputs
- Unsanitized Prompt Inputs: User prompts could directly manipulate the generation of audit logs.
Human Factors
- Accidental Bypass Triggering: Users could trigger the audit log bypass unintentionally during normal work.
- Malicious Insider Exploitation: Insiders could intentionally use Copilot to steal files without detection.
Process and Methods
- Inconsistent Vulnerability Process: Microsoft deviated from its own security reporting and status tracking guides.
- Flawed CVE Assignment Rules: Policies prevented CVE assignment because the fix was pushed automatically.
Regulatory Environment
- Compliance Verification Gap: Regulated entities like HIPAA users relied on incorrect logs for compliance.
Information quality
- Classification confidence: High
- Reason for confidence: The report provides a clear, first-hand technical account of the vulnerability, including reproduction steps, expected vs. actual behavior, and communication logs with Microsoft.
A security researcher discovered a vulnerability in Microsoft 365 Copilot that allowed users to bypass audit logging when accessing files. While representing a minor information security risk due to potential undetected insider data exfiltration, the issue has been patched by Microsoft, and there are no reports of active exploitation by hostile actors.
- Overall national security impact: Minor
- Response level: Moderate
- Scope: Multiple nations
- Primary target: No clear primary
- Other affected: Unknown
- Alleged perpetrator: Unknown
Threat characteristics
- Imminence: Long-term. The vulnerability has been patched by Microsoft, reducing immediate risk, though historical audit integrity remains a long-term compliance concern.
- Autonomy: Human-controlled. Microsoft 365 Copilot operates as a human-controlled assistant, executing actions based on explicit user prompts.
- Novelty: Established threat. Software vulnerabilities and logging failures are well-established threat vectors, even when occurring within AI-integrated environments.
Impact by dimension
- Physical security: Negligible. No physical systems, critical infrastructure, or human safety components were compromised or affected by this software vulnerability.
- Information security: Minor. The vulnerability created a potential vector for undetected data exfiltration, but there are no reports of active exploitation or compromised intelligence data.
- Sovereignty: Negligible. No disruption to core government operations, electoral systems, or sovereign decision-making processes was reported.
- Economic security: Minor. While the flaw could theoretically facilitate intellectual property theft in strategic industries, no actual economic exploitation was reported.
- Societal stability: Negligible. The incident does not involve mass surveillance, systematic discrimination, or threats to social cohesion.