One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes
A one-click flaw in Microsoft 365 Copilot could have let attackers steal emails, files, and MFA codes. Researchers at Varonis Threat Labs discovered the flaw, which is now mitigated by Microsoft.
Intelligence analysis by Llama 3.3 70B

The flaw, called SearchLeak, allowed attackers to exfiltrate data from Microsoft 365 Copilot Enterprise Search with a single click on a trusted Microsoft link.
Imagine you're using a search engine to find something on your computer. But instead of just searching, the search engine can also do things on its own, like send emails or open files. That's kind of like what Microsoft 365 Copilot does. But there was a bug that let bad people trick Copilot into sending them secret information, like passwords or private emails. It was like a magic trick, but not a good one.
Analysis
The SearchLeak flaw was discovered by researchers at Varonis Threat Labs, who found that it was possible to chain three bugs together to create a one-click exfiltration path. The first bug was a command injection vulnerability that allowed attackers to inject malicious code into the Copilot Enterprise Search URL. The second bug was a race condition in how the response was rendered, which allowed the injected code to be executed before the sanitizer could neutralize it. The third bug was a Content Security Policy (CSP) bypass, which allowed the attacker to exfiltrate the stolen data to their own server. The attacker could use the stolen data to take over the user's account, access sensitive information, and perform other malicious activities. Microsoft has mitigated the flaw on its backend, but users are still advised to be cautious and monitor their accounts for any suspicious activity. The discovery of this flaw highlights the importance of continuous security testing and monitoring, as well as the need for users to be aware of the potential risks associated with using cloud-based services. The fact that this flaw was discovered in a managed service like Microsoft 365 Copilot Enterprise Search also underscores the need for cloud service providers to prioritize security and ensure that their services are properly secured. The SearchLeak flaw is not an isolated incident, as Varonis researcher Dolev Taler had previously demonstrated a similar one-click technique in an earlier Reprompt attack against Copilot Personal. This pattern of vulnerabilities highlights the need for ongoing security research and testing to identify and mitigate potential flaws before they can be exploited by attackers.
Key points
- The SearchLeak flaw allowed attackers to exfiltrate data from Microsoft 365 Copilot Enterprise Search with a single click
- The flaw was caused by a combination of three bugs, including a command injection vulnerability, a race condition, and a CSP bypass
- Microsoft has mitigated the flaw on its backend, but users are still advised to be cautious and monitor their accounts for any suspicious activity
The fact that Microsoft was able to mitigate the flaw on its backend means that users do not need to take any immediate action to protect themselves. Additionally, the discovery of this flaw highlights the importance of continuous security testing and monitoring, which can help to identify and mitigate potential vulnerabilities before they can be exploited. As cloud service providers continue to prioritize security, users can expect to see improved protections and safeguards in place to prevent similar vulnerabilities from being exploited in the future.
The discovery of the SearchLeak flaw highlights the potential risks associated with using cloud-based services, particularly those that have access to sensitive information. The fact that this flaw was able to be exploited with a single click makes it particularly concerning, as it could have allowed attackers to steal sensitive information from Microsoft 365 users. If similar vulnerabilities are discovered in the future, it could have serious consequences for users and organizations that rely on cloud-based services.



