Microsoft Word Copilot Vulnerability Exposes Hidden Prompts, AI Worms
Key Takeaways A critical vulnerability in Microsoft Copilot for Word allows hidden prompts within documents to execute malicious instructions. This flaw can lead to “AI worms” that...
Key Takeaways
- A critical vulnerability in Microsoft Copilot for Word allows hidden prompts within documents to execute malicious instructions.
- This flaw can lead to “AI worms” that self-propagate, silently modifying content and spreading across an organization’s documents.
- The attack leverages Copilot’s processing of seemingly irrelevant or invisible text as legitimate commands, enabling cross-document contamination.
- While Microsoft has implemented some fixes, a comprehensive solution for this vulnerability class is still pending, leaving organizations exposed.
Microsoft Copilot for Word Vulnerability Enables AI Worms
A recently discovered vulnerability in Microsoft Copilot for Word demonstrates how concealed instructions within documents can transform ordinary editing processes into a self-replicating “AI worm.” This malicious mechanism is capable of tampering with critical business content and then covertly spreading itself to new files within an enterprise environment.
Table Of Content
The flaw, identified by researcher EN Klype Salt coordinated disclosure, stems from how Copilot processes contextual or attached documents. Text that appears irrelevant or even invisible to a human user can still be fully parsed by the underlying large language model (LLM). This allows attacker-controlled directives to breach the trust boundary between untrusted source material and trusted working documents.
This research expands upon previous investigations into Cross-Domain Prompt Injection Attacks (XPIAs), elevating the threat from single-interaction compromises to multi-document propagation across an organization’s entire workflow.
How the AI Worm Operates
In the scenario detailed by the researcher, an attacker embeds a JSON-formatted prompt within a Word document. This malicious text might be rendered in white on a white background, using a minuscule font, or placed at the end of a lengthy report to evade detection.
When a user subsequently references or attaches this compromised document in Copilot for Word—either through the “magic pen” feature or “Edit with Copilot” mode—Copilot strips away the formatting. It then interprets the hidden text as instructions, initiating manipulation of the active document. For instance, Copilot could silently halve financial figures in a quarterly report. Simultaneously, it copies the entire malicious prompt, also using concealed formatting, into the newly generated or edited document.
This newly modified document then becomes a fresh vector for the attack. Should it later be used as source material for another Copilot-assisted draft, the embedded prompt reactivates, alters the new content, and re-embeds itself. Effectively, this transforms trusted internal files into carriers for an AI worm that proliferates through normal collaboration and document reuse, even if the original infected external document is no longer present in the system.
The researcher successfully reproduced this behavior across various Copilot configurations and underlying models, including deployments updated to GPT-5.5 and GPT-5.6. This occurred despite Microsoft having implemented targeted mitigations designed to block earlier forms of these payloads.
Microsoft’s Security Response Center (MSRC) and product teams were engaged in a 144-day coordinated disclosure process with EN Klype Salt. During this period, the researcher provided comprehensive reproduction steps, proof-of-concept prompts, and detailed video demonstrations.
While Microsoft has deployed partial fixes and successfully addressed some related attack vectors, a robust mitigation for this broader class of vulnerability is not yet available. Consequently, the attack chain remains exploitable at the time of publication.
Organizational Impact and Risk
For organizations, the immediate consequences include a significant loss of data integrity and traceability within their Microsoft 365 ecosystems. Once malicious instructions are embedded in internally authored documents, they can be distributed via platforms like SharePoint, Teams, or email to other departments and even partner organizations, all under the guise of legitimate content.
A critical challenge arises because Copilot’s edits are often approved and subsequently cease to be flagged as distinct changes. This makes it exceedingly difficult to pinpoint precisely when and where financial figures or specific wording were manipulated, severely complicating incident response and forensic analysis efforts.
The findings underscore a fundamental architectural weakness prevalent in many LLM-integrated systems: the necessity of processing attacker-controlled content within the same context as trusted instructions. This design choice elevates prompt injection and self-propagation from isolated product bugs to a systemic risk across the LLM landscape.
What You Should Do
- Treat External Documents as Untrusted: Always assume documents sourced externally are untrustworthy when used with Copilot.
- Review Attachments: Carefully review all attachments before initiating AI-assisted drafting or editing with Copilot.
- Perform Human Review: Implement a rigorous human review process for any Copilot-generated or Copilot-edited documents before they are reused or shared within or outside the organization.
- Stay Informed: Monitor Microsoft’s official security advisories and updates for comprehensive patches addressing this vulnerability class.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.