A newly discovered vulnerability in Microsoft Copilot for Word reveals how concealed prompts within documents can turn standard editing processes into ‘AI worms’, posing significant threats to business content integrity and document security.
Understanding the Vulnerability
This vulnerability, identified by researcher EN Klype Salt, arises from the way Copilot manages attached or contextual documents. Text that appears irrelevant or invisible to users can be fully interpreted by the underlying large language model. This allows attacker-controlled commands to bypass trust boundaries, transforming untrusted source material into trusted document content.
The research builds on previous explorations into Cross-Domain Prompt Injection Attacks (XPIAs), broadening the scope from single document compromises to multi-document propagation within enterprise workflows.
Mechanics of the AI Worm Threat
In the scenario described, attackers embed a JSON-formatted prompt in a Word document, often by making the text white on a white background at the end of a report. When users interact with this document via Copilot, the tool strips formatting, processes the hidden text as commands, and alters the active document.
Once activated, Copilot may modify critical content, such as altering financial figures, while embedding the malicious prompt in any newly created or edited documents. These documents then act as new vectors for the attack, perpetuating the cycle when reused in Copilot-assisted drafts.
Implications and Response Strategies
Tests confirmed this behavior across various Copilot configurations and models, including GPT-5.5 and GPT-5.6, despite efforts to block previous payloads. EN Klype Salt coordinated with Microsoft’s Security Response Center over 144 days, offering detailed reports and proof-of-concept prompts.
Although Microsoft has implemented some fixes, a comprehensive solution is still absent, leaving this vulnerability open to exploitation. For organizations, this presents a risk to data integrity across Microsoft 365 environments, as maliciously altered documents can be distributed through SharePoint, Teams, or email, appearing legitimate.
To mitigate risks, organizations are advised to treat externally sourced documents as untrusted when using Copilot, review attachments thoroughly before engaging AI-assisted drafting, and conduct careful reviews of Copilot-generated documents before reuse or distribution.
Future Outlook
This vulnerability highlights a fundamental flaw in many systems integrated with large language models, where attacker-controlled content is processed alongside trusted instructions. This systemic risk underscores the need for improved security measures in AI-assisted tools to prevent prompt injection and self-propagation.
Organizations are encouraged to strengthen their security operations centers by enhancing threat detection and rapid investigation capabilities, integrating robust solutions to safeguard against such vulnerabilities.
