Microsoft: Microsoft Word Copilot Vulnerability Turns Hidden Prompts Into Self‑Propagating AI Worms

Microsoft: Microsoft Word Copilot Vulnerability Turns Hidden Prompts Into Self‑Propagating AI Worms

Microsoft Copilot for Word Vulnerability Enables Self-Propagating AI Worm

Researcher EN Klype Salt has uncovered a critical vulnerability in Microsoft Copilot for Word that allows hidden prompts in documents to create a self-propagating AI worm, compromising business content and spreading across enterprise workflows.

The flaw stems from Copilot’s handling of contextual documents text that appears invisible or irrelevant to users but is fully parsed by the underlying large language model (LLM). Attackers can embed JSON-formatted malicious prompts in documents (e.g., white-on-white text in a small font) that, when processed by Copilot, execute unauthorized instructions.

Once triggered via features like "Edit with Copilot" or the "magic pen" the AI modifies active documents (e.g., altering financial figures in reports) while replicating the malicious prompt into newly generated files. These compromised documents then act as fresh attack vectors, propagating the worm through normal collaboration channels like SharePoint, Teams, or email, even after the original source is removed.

The vulnerability affects multiple Copilot configurations, including deployments with GPT-5.5 and GPT-5.6, despite Microsoft’s partial mitigations. Salt coordinated disclosure with Microsoft’s Security Response Center (MSRC) over a 144-day period, providing proof-of-concept (PoC) prompts and reproduction steps. While Microsoft has addressed some attack vectors, no comprehensive fix exists, leaving the broader vulnerability class exploitable.

For organizations, the risk includes loss of data integrity and traceability within Microsoft 365 ecosystems. Since Copilot’s edits often blend into documents without clear audit trails, detecting tampered content such as manipulated financial data or wording becomes challenging, complicating incident response and forensic analysis.

The findings underscore a systemic weakness in LLM-integrated systems: attacker-controlled content is processed alongside trusted instructions, making prompt injection and self-propagation a persistent threat rather than an isolated flaw.

Source: https://cybersecuritynews.com/microsoft-word-copilot-vulnerability/

Microsoft TPRM report: https://www.rankiteo.com/company/microsoft-security-response-center

"id": "mic1785392682",
"linkid": "microsoft-security-response-center",
"type": "Vulnerability",
"date": "7/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'Enterprises using Microsoft '
                                              'Copilot for Word with '
                                              'GPT-5.5/GPT-5.6',
                        'industry': 'Software, Cloud Services, AI',
                        'location': 'Global',
                        'name': 'Microsoft',
                        'size': 'Large Enterprise',
                        'type': 'Technology Corporation'}],
 'attack_vector': 'Malicious prompts embedded in documents (e.g., '
                  'white-on-white text, JSON-formatted instructions)',
 'data_breach': {'file_types_exposed': 'Word documents (.docx), Microsoft 365 '
                                       'files',
                 'sensitivity_of_data': 'High (business-critical, financial, '
                                        'operational)',
                 'type_of_data_compromised': 'Business documents, financial '
                                             'data, proprietary content'},
 'description': 'Researcher EN Klype Salt uncovered a critical vulnerability '
                'in Microsoft Copilot for Word that allows hidden prompts in '
                'documents to create a self-propagating AI worm, compromising '
                'business content and spreading across enterprise workflows. '
                'The flaw stems from Copilot’s handling of contextual '
                'documents text that appears invisible or irrelevant to users '
                'but is fully parsed by the underlying large language model '
                '(LLM). Attackers can embed JSON-formatted malicious prompts '
                'in documents that, when processed by Copilot, execute '
                'unauthorized instructions, modify active documents, and '
                'replicate the malicious prompt into newly generated files, '
                'propagating the worm through collaboration channels like '
                'SharePoint, Teams, or email.',
 'impact': {'brand_reputation_impact': 'Potential erosion of trust in '
                                       'AI-integrated systems and Microsoft '
                                       '365 security',
            'data_compromised': 'Business content, financial data, document '
                                'integrity',
            'operational_impact': 'Loss of data integrity, compromised '
                                  'document traceability, difficulty in '
                                  'incident response and forensic analysis',
            'systems_affected': 'Microsoft Copilot for Word, Microsoft 365 '
                                '(SharePoint, Teams, email workflows)'},
 'investigation_status': 'Disclosed to Microsoft MSRC with PoC; partial '
                         'mitigations implemented',
 'lessons_learned': 'Systemic weakness in LLM-integrated systems where '
                    'attacker-controlled content is processed alongside '
                    'trusted instructions, making prompt injection and '
                    'self-propagation persistent threats. Highlights the need '
                    'for improved audit trails and contextual parsing in AI '
                    'systems.',
 'post_incident_analysis': {'corrective_actions': 'Partial mitigations by '
                                                  'Microsoft; no comprehensive '
                                                  'fix yet',
                            'root_causes': 'Copilot’s LLM parsing of '
                                           'hidden/invisible text in '
                                           'documents, lack of strict '
                                           'contextual validation, and '
                                           'self-replicating malicious '
                                           'prompts'},
 'recommendations': 'Organizations should monitor document modifications by '
                    'Copilot, implement stricter parsing controls for '
                    'hidden/invisible text, and enhance forensic capabilities '
                    'to detect tampered content. Microsoft should develop a '
                    'comprehensive fix for the vulnerability class.',
 'references': [{'source': 'Researcher EN Klype Salt'}],
 'response': {'remediation_measures': 'Partial mitigations by Microsoft (no '
                                      'comprehensive fix)'},
 'title': 'Microsoft Copilot for Word Vulnerability Enables Self-Propagating '
          'AI Worm',
 'type': 'AI Worm / Prompt Injection',
 'vulnerability_exploited': 'Copilot’s handling of contextual documents and '
                            'LLM parsing of hidden/invisible text'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.