Home Cyber Security News Microsoft Copilot Word Flaw Lets Hidden Prompts Spread Self-Propagating AI Worms Across...

Microsoft Copilot Word Flaw Lets Hidden Prompts Spread Self-Propagating AI Worms Across Documents

0
Microsoft Copilot Word Flaw Lets Hidden Prompts Spread Self-Propagating AI Worms Across Documents

A newly disclosed Microsoft Copilot for Word issue shows how hidden instructions embedded in a Word document can be interpreted by the assistant as commands and copied into newly generated files, creating a self-propagating “document-borne” AI worm that can move through normal enterprise workflows.

Researcher Håkon Måløy published the findings on July 28, 2026, describing the flaw as part of his “Context Collapse” research series and warning that the attack can persist even after the original malicious document is removed from later drafting sessions.

At the core of the issue is indirect prompt injection, a class of attacks in which a generative AI system treats attacker-controlled content from an external source as trusted user intent rather than untrusted data.

Microsoft Copilot Word Flaw

Microsoft’s own security guidance identifies documents, emails, websites, and other third-party content as common delivery channels for this problem.

Noting that copilots often cannot reliably distinguish between a user’s request and embedded hostile instructions once both are placed into the same model context.

Initial attack vector (Source: enklypesalt)
Initial attack vector (Source: enklypesalt)

In the proof-of-concept described by Måløy, the malicious prompt was concealed as white text on a white background, in a small font, within a seemingly relevant document, allowing the payload to remain invisible to the user yet still readable.

Once the poisoned file entered Copilot’s context, the assistant could alter the active document, such as changing financial figures in a draft report, and then append the hidden prompt to the bottom of the newly created file, effectively converting that output into the next infection carrier.

That propagation step is what makes the finding especially significant for defenders, because the second-stage attack no longer depends on the attacker’s original lure.

A coworker only needs to reuse the already tainted internal document in a later Copilot-assisted workflow for the instructions to trigger again.

The threat model also lowers the barrier to exploitation because the attacker does not need Microsoft 365 tenant access, macro execution, or code execution; only a malicious document delivered through routine channels such as email, SharePoint, Teams, or partner collaboration.

According to Enklypesalt, Microsoft received reproduction details and worked through a 144-day coordinated disclosure process. While some mitigations reduced specific payloads.

 After having halved all financial numbers in the Q1 financial report draft (Source: enklypesalt)
 After having halved all financial numbers in the Q1 financial report draft (Source: enklypesalt)

The broader vulnerability class reportedly remained reproducible at the time of publication, and no complete customer-side remediation was available.

That leaves organizations facing a document-integrity problem rather than a traditional malware problem, in which AI-assisted reports, summaries, and business drafts could be quietly manipulated and redistributed as trusted internal artifacts without an obvious audit trail.

Microsoft’s published guidance on indirect prompt injection argues that no single control is sufficient and recommends layered defenses, including prompt shields, isolation of untrusted content, information-flow controls, runtime monitoring, least privilege, and human review for sensitive actions.

Until a stronger architectural mitigation is available for Copilot in Word, security teams should treat externally sourced documents as untrusted AI inputs.

Review files before adding them to Copilot’s context, and carefully inspect Copilot-generated or Copilot-edited documents before sharing them inside or outside the organization.

Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN. 

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here