Affected Systems

Microsoft 365 Copilot Enterprise Search. All organizations using M365 Copilot with Enterprise Search enabled are potentially affected. Specific version details not disclosed.

Exploitation Status

Proof-of-concept demonstrated by Varonis Threat Labs. No CVE assigned yet. No evidence of active exploitation in the wild reported. Vulnerability chain has been disclosed to Microsoft.

Business Impact

Attackers can exfiltrate sensitive corporate data (emails, calendar entries, indexed files) through a single-click attack using a legitimate microsoft.com domain. Traditional security controls (anti-phishing, URL filters) fail to detect the attack because the link appears trusted. High risk for organizations using M365 Copilot, particularly those with sensitive data indexed by Enterprise Search. Patch status and timeline unknown.

Urgency

🟠 Within 24 hours

Recommended Actions

  • Identify all users with Microsoft 365 Copilot Enterprise Search enabled and assess exposure to indexed sensitive data
  • Monitor Microsoft Security Response Center (MSRC) for official advisory and patch release for SearchLeak vulnerability
  • Review M365 audit logs for suspicious Copilot search activity and unexpected data access patterns, particularly external link clicks
  • Implement user awareness training on clicking links in unsolicited emails, even from microsoft.com domains, until patch is available
  • Consider temporarily restricting Copilot Enterprise Search access for high-privilege users handling sensitive data until Microsoft issues a fix