Hidden commands within Microsoft Word documents can trigger unexpected behavior in Microsoft 365 Copilot, potentially altering report data and embedding the same hidden instructions in newly created documents. Security researcher Håkon Måløy revealed this vulnerability on July 28, several months after informing Microsoft about the issue.
The Vulnerability Details
Måløy’s findings indicate that the vulnerability involves Microsoft 365 Copilot misinterpreting embedded document instructions as user requests. Microsoft acknowledged the issue on March 31 and implemented two mitigations: blocking initial prompt wording and upgrading the AI model to GPT-5.5. Despite these efforts, Måløy found that modified instructions continued to work with GPT-5.6, suggesting the vulnerability remains exploitable.
The exploit requires a Copilot drafting or editing session, where the malicious document is included as an attachment or accessed from OneDrive using Microsoft’s Work IQ engine. Importantly, the attack does not rely on traditional malware execution and is not a zero-click vulnerability.
Security Implications and Recommendations
Måløy advises caution when handling external documents. He suggests treating such files as untrusted, reviewing attachments before generating or editing content, and scrutinizing Copilot outputs before further distribution. The exploit involves Copilot reading source files and mistaking hidden instructions as part of the user’s input, leading to unintended alterations and concealed prompts.
In the proof of concept, Copilot altered financial figures and embedded the full prompt in the resulting document using white, eight-point text. Word’s processing strips color and font size, making the hidden instructions visible to the AI model without user detection.
Microsoft’s Response and Future Outlook
As of now, there is no public CVE or specific Microsoft advisory addressing this issue. Microsoft employs classifiers to block high-risk prompts, but these are not universally available across all Copilot scenarios. Defender for Office 365 includes mail-flow inspection for incoming emails, and Copilot’s runtime safeguards aim to manage injected instructions. However, the effectiveness of these measures for this specific payload remains unclear.
Måløy argues that current defenses do not fully address the class of vulnerabilities due to the need for models to process potentially malicious content. Microsoft’s stance aligns, emphasizing that AI memory and prompt isolation should be managed by deterministic systems.
The ongoing nature of this vulnerability highlights the challenges in securing AI-driven applications and underscores the importance of robust safeguards as AI systems become increasingly integrated into business processes.
