CVEPublished 2025-06-111 article on news6 live referencesNVD data

CVE-2025-32711

Vulnerability data via CVEDB (Shodan)

CVSS v3.1
9.3
CRITICAL
EPSS percentile
91
Exploit Prediction Scoring System · top 9% of all CVEs
Description

Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Timeline
Published 2025-06-11

External references

Search for exposed instances

Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).

More intel sources (5)

Known PoCs on GitHub (8)

TalEliyahu/Awesome-AI-Securityunknown
Curated resources, research, and tools for securing AI systems
★ 735·updated today
ZeroLeaks/zeroleaksTypeScript
AI Security Scanner - Test your AI systems for prompt injection and extraction vulnerabilities
★ 587·updated 4mo ago
requie/LLMSecurityGuideunknown
A comprehensive reference for securing Large Language Models (LLMs). Covers OWASP GenAI Top-10 risks, prompt injection, adversarial attacks, real-world incidents, and practical def…
★ 118·updated 2mo ago
ucsb-mlsec/Awesome-Agent-Securityunknown
★ 48·updated 8mo ago
bridge-mind/BridgeWardShell
Trust nothing. Ship safely. — Skeptical-reading and prompt-injection defense skill for AI agents. Provenance tagging, red-flag patterns, refusal templates, and a read-only injectio…
★ 33·updated 1mo ago
jeremylongshore/claude-code-slack-channelTypeScript
Slack-native governance substrate for Claude Code and peer agents: every tool call passes a tiered policy engine and lands in a hash-chained, Ed25519-signed audit journal you can v…
★ 33·updated 1d ago
SecureNexusLab/llm-prompt-injection-security-handbookunknown
A comprehensive technical research report on LLM Prompt Injection threats, covering direct/indirect injection, jailbreaking, adversarial suffixes, and defense-in-depth architecture…
★ 32·updated 2mo ago
quantifylabs/aegis-memoryPython
Secure context engineering for AI agents. Content security · integrity verification · trust hierarchy · ACE patterns. Self-hosted, Apache 2.0.
★ 26·updated today