Skip to content
Malware

Microsoft Word Copilot Vulnerability Turns Hidden Prompts Into Self‑Propagating AI Worms

A new vulnerability in Microsoft Copilot for Word shows how hidden prompts inside documents can transform routine editing into a self‑propagating “AI worm” that tampers with business content and then quietly spreads itself to new files. The vulnerability uncovered by EN Klype Salt stems from Copilot...

· Jul 30, 2026 · 3 min read · 👁 1 views
Microsoft Word Copilot Vulnerability Turns Hidden Prompts Into Self‑Propagating AI Worms

A new vulnerability in Microsoft Copilot for Word shows how hidden prompts inside documents can transform routine editing into a self‑propagating “AI worm” that tampers with business content and then quietly spreads itself to new files.

The vulnerability uncovered by EN Klype Salt stems from Copilot’s handling of attached or contextual documents: text that looks irrelevant or invisible to the human user can still be fully parsed by the underlying large language model, allowing attacker‑controlled instructions to cross the trust boundary between untrusted source material and trusted working documents.

The research builds on prior work into Cross‑Domain Prompt Injection Attacks (XPIAs), expanding the threat from single‑interaction compromises to multi‑document propagation across enterprise workflows.

Microsoft Word Copilot Vulnerability

In the reported scenario, an attacker hides a JSON‑formatted prompt inside a Word document, for example by rendering the malicious text as white on white in a small font at the end of a market analysis or report.

When a user later attaches or indirectly references this document in Copilot for Word, either through the “magic pen” experience or the “Edit with Copilot” mode, Copilot strips formatting, reads the hidden text as instructions, and begins to manipulate the active document.

Once triggered, Copilot may alter key content, such as silently halving financial figures in a Q1 report, while also copying the entire malicious prompt into the newly generated or edited document using concealed formatting.

That downstream document now becomes a fresh attack vector: if it is later reused as source material for another Copilot‑assisted draft, the hidden prompt fires again, modifies the new content, and embeds itself once more.

In effect, the attack turns trusted internal files into carriers of an AI worm that propagates via normal collaboration and document reuse, even after the original external document is no longer present.

This behavior was reproduced against multiple Copilot configurations and underlying models, including deployments upgraded to GPT‑5.5 and GPT‑5.6, despite targeted mitigations that blocked earlier payloads.

Researcher EN Klype Salt coordinated disclosure with Microsoft’s Security Response Center (MSRC) and product teams over a 144‑day period, providing reproduction steps, PoC prompts, and detailed videos.

While Microsoft has shipped partial fixes and successfully closed some related vectors, there is currently no robust mitigation for the broader vulnerability class, and the attack chain remains exploitable at publication.

For organizations, the immediate risk is loss of data integrity and traceability inside their Microsoft 365 ecosystems. Once malicious instructions are embedded in internally authored documents, they can be redistributed through SharePoint, Teams, or email to other departments and even partner organizations, all under the guise of legitimate content.

Because Copilot’s edits are often approved and then no longer surfaced as separate changes, identifying where and when financial numbers or wording were manipulated becomes extremely difficult, complicating incident response and forensic analysis.

Defenders cannot fully remediate the issue on the customer side today, but they can reduce exposure by treating externally sourced documents as untrusted when used with Copilot, reviewing attachments before starting AI‑assisted drafting or edits, and performing careful human review of any Copilot‑generated or Copilot‑edited documents before reusing or sharing them.

At a strategic level, the findings highlight an architectural weakness shared across many LLM‑integrated systems: attacker‑controlled content must be processed in the same context as trusted instructions, making prompt‑injection and self‑propagation a systemic risk rather than an isolated product bug.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Related Articles

Recommended for you