Microsoft Copilot for Word is susceptible to a self-propagating Cross-Prompt Injection Attack (XPIA) stemming from a fundamental architectural inability to distinguish between untrusted user data and authoritative developer instructions. Attackers embed JSON-formatted payloads using white-on-white text obfuscation in .docx files. Upon ingestion, the AI agent elevates these hidden strings to high-priority system commands, enabling the worm to autonomously append itself to any subsequently generated or edited documents. This mechanism bypasses traditional EDR and AV signatures by utilizing authorized AI agents within enterprise workflows—specifically SharePoint and Teams—potentially leading to organizational-wide context collapse and unauthorized data exfiltration.
-
Vulnerability Analysis: Architectural LLM Flaw
- Root Cause: Inherent failure in LLM context windows to logically isolate untrusted external content from system-level instructions.
- Attack Paradigm: Evolution from static, single-use prompt injection to autonomous, worm-like replication via XPIA.
- Target Scope: Integrated enterprise productivity suites where AI agents possess read/write permissions across collaborative file systems.
-
Exploitation Vector: Document-Borne Payloads
- Injection Method: Use of white-on-white text or JSON metadata in
.docxfiles to evade human detection while remaining legible to the LLM's text-stripping parser. - Execution Trigger: Activated when a user employs Copilot for summarization, rewriting, or editing of a compromised document.
- Context Hijacking: The agent strips document formatting during ingestion, promoting hidden, untrusted text to the status of a high-priority command.
- Injection Method: Use of white-on-white text or JSON metadata in
-
Propagation Mechanics: Autonomous Replication
- Replication Loop: The hijacked agent is commanded to embed the malicious prompt payload into every new document it drafts or modifies.
- Distribution Channels: Leverages trusted enterprise collaboration workflows, including Microsoft Teams, SharePoint, and email.
- Persistence: Confirmed effective across model iterations (GPT-5.5 and GPT-5.6), indicating the flaw is structural rather than version-specific.
-
Defensive Evasion & Systemic Impact
- Security Bypass: Evades AV/EDR detection because malicious actions are executed by a signed, authorized Microsoft AI agent.
- Data Exfiltration: Facilitates the leak of sensitive data via AI-generated output or embedded URLs, bypassing traditional Data Loss Prevention (DLP) tools.
- Operational Risk: High probability of "context collapse," where a single poisoned file corrupts the entire chain of AI-assisted document creation.
-
Mitigation & Strategic Response
- Vendor Status: Microsoft has deployed mitigations to block specific known PoC payloads, but the underlying architectural vulnerability remains unresolved.
- Defensive Gaps: Traditional endpoint security lacks the semantic awareness required to intercept logic manipulation within the AI's internal reasoning loop.
- Proposed Defense: Transition toward semantic-aware defensive frameworks and the implementation of specialized AI proxy layers to validate agent intent.
Related posts
- DEV Community — AI Worms in Word: How Document-Borne Threats Self-Propagate
- Malware News — Hidden prompt turns Microsoft Copilot into an AI worm
- techjacksolutions.com
- datawater.com — Copilot for Word AI Worm: Hidden White-on-White Instructions Spread Self-Propagating XPIA Through Enterprise Document Workflows — 144 Days After Disclosure, Architectural Problem Unresolved
- csoonline.com — Microsoft confirms an AI worm is propagating through Copilot and other MS apps
- SOCFortress — Context Collapse: The AI Worm in Microsoft Word
- NSFOCUS — AI Security Incident Case: Document Worm Achieves Self Replication and Propagation Via Word Copilot
- feeds.feedburner.com — New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis
- Infosecurity-magazine
- Sentinelone
- gbhackers.com — Microsoft Word Copilot Flaw Lets Hidden Prompts Spread Self-Propagating AI Worms Across Documents
- cyberinsider.com — Microsoft Copilot for Word vulnerable to self-propagating worm-like attack
- Malwarebytes
- Byteiota
- csoonline.com — Copilot worm can spread through Microsoft Word docs
- Hivepro
- Innovaiden
- Blog
- Securityboulevard
- Labs
- Techrepublic
- Aigovernance
- Daily
- Thenextweb
- Runtimewire
- Youtube
- Gigazine
- Developersdigest