Skip to Content
logologo
AI Incident Database
Open TwitterOpen RSS FeedOpen FacebookOpen LinkedInOpen GitHub
Open Menu
Discover
Submit
  • Welcome to the AIID
  • Discover Incidents
  • Spatial View
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Submit Incident Reports
  • Submission Leaderboard
  • Blog
  • AI News Digest
  • Risk Checklists
  • Random Incident
  • Sign Up
Collapse
Discover
Submit
  • Welcome to the AIID
  • Discover Incidents
  • Spatial View
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Submit Incident Reports
  • Submission Leaderboard
  • Blog
  • AI News Digest
  • Risk Checklists
  • Random Incident
  • Sign Up
Collapse
Entities

Microsoft 365 Copilot

Incidents implicated systems

Incident 12181 Report
Microsoft 365 Copilot Vulnerability Allegedly Allowed File Access Without Audit Log Entry

2025-07-04

A vulnerability in Microsoft 365 Copilot reportedly allowed users to access and summarize files without generating audit log entries, allegedly undermining traceability and compliance. Security researcher Zack Korman disclosed the issue to Microsoft, which reportedly classified it as "important" and fixed it on August 17, 2025, but reportedly chose not to notify customers or assign a CVE.

More

Related Entities
Other entities that are related to the same incident. For example, if the developer of an incident is this entity but the deployer is another entity, they are marked as related entities.
 

Entity

Microsoft

Incidents involved as both Developer and Deployer
  • Incident 1218
    1 Report

    Microsoft 365 Copilot Vulnerability Allegedly Allowed File Access Without Audit Log Entry

More
Entity

Microsoft 365 Copilot enterprise customers

Incidents Harmed By
  • Incident 1218
    1 Report

    Microsoft 365 Copilot Vulnerability Allegedly Allowed File Access Without Audit Log Entry

More
Entity

Organizations relying on audit logs for compliance and security

Incidents Harmed By
  • Incident 1218
    1 Report

    Microsoft 365 Copilot Vulnerability Allegedly Allowed File Access Without Audit Log Entry

More

Research

  • Defining an “AI Incident”
  • Defining an “AI Incident Response”
  • Database Roadmap
  • Related Work
  • Download Complete Database

Project and Community

  • About
  • Contact and Follow
  • Apps and Summaries
  • Editor’s Guide

Incidents

  • All Incidents in List Form
  • Flagged Incidents
  • Submission Queue
  • Classifications View
  • Taxonomies

2024 - AI Incident Database

  • Terms of use
  • Privacy Policy
  • Open twitterOpen githubOpen rssOpen facebookOpen linkedin
  • 6f6c5a5