AI Incident Database: Microsoft 365 Copilot Vulnerability Allegedly Allowed File Access Without Audit Log Entry
A vulnerability in Microsoft 365 Copilot reportedly allowed users to access and summarize files without generating audit log entries, allegedly undermining traceability and compliance. Security researcher Zack Korman disclosed the issue to Microsoft, which reportedly classified it as "important" and fixed it on August 17, 2025, but reportedly chose not to notify customers or assign a CVE.
AI Incident Database · Incident 1218Operator lens (medium): inspect D7 (tool permissions).
Event summary
A vulnerability in Microsoft 365 Copilot reportedly allowed users to access and summarize files without generating audit log entries, allegedly undermining traceability and compliance. Security researcher Zack Korman disclosed the issue to Microsoft, which reportedly classified it as "important" and fixed it on August 17, 2025, but reportedly chose not to notify customers or assign a CVE.
Linked entities
- Microsoft
vendor | 70%
- microsoft-365-copilot-enterprise-customers
organisation | 70%
- organizations-relying-on-audit-logs-for-compliance-and-security
organisation | 70%
Related graph edges
| Edge | Type | Confidence |
|---|---|---|
| ent-vendor-microsoft to ent-psf-d2 | maps to | 60% |
| ent-vendor-microsoft to ent-psf-d2 | maps to | 60% |
| ent-vendor-microsoft to ent-psf-d2 | maps to | 60% |
| ent-vendor-microsoft to ent-psf-d6 | maps to | 60% |
| ent-vendor-microsoft to ent-psf-d6 | maps to | 60% |
| ent-vendor-microsoft to ent-psf-d6 | maps to | 60% |
| ent-vendor-microsoft to ent-psf-d7 | maps to | 60% |
| ent-vendor-microsoft to ent-psf-d7 | maps to | 60% |
| ent-vendor-microsoft to ent-psf-d7 | maps to | 60% |
| ent-vendor-microsoft to ent-psf-d7 | maps to | 60% |
| ent-vendor-microsoft to ent-psf-d7 | maps to | 60% |
| ent-vendor-microsoft to ent-psf-d7 | maps to | 60% |