AI worms can self-replicate via Copilot for Word documents

Original: Document-borne AI worms can self-propagate through Copilot for Word

Why This Matters

Demonstrates a new class of self-propagating AI attacks targeting enterprise productivity tools at scale.

Security researcher Håkon Måløy disclosed a vulnerability where hidden instructions in Word documents can cause Microsoft Copilot to manipulate content and copy attack instructions into new documents, enabling self-propagating AI worms across document workflows after a 144-day coordinated disclosure with MSRC.

Researcher Håkon Måløy published findings — part of a coordinated disclosure with Microsoft Security Response Center (MSRC) — showing that attacker-controlled instructions embedded in a Word document can cause Copilot for Word to alter document content and copy the malicious instructions into newly generated or edited documents. Those downstream documents then become carriers, capable of triggering the same attack in subsequent Copilot-assisted workflows, without the original malicious document being present.

The attack falls under the category of Cross-Domain Prompt Injection Attacks (XPIAs). A practical example: an employee downloads a compromised market analysis and uses it as source material in Copilot. Copilot interprets hidden instructions, alters figures in the financial report being drafted, and embeds the attack into the output. When a colleague later uses that report with Copilot, the cycle repeats.

Måløy notes this is among the first public demonstrations of document-borne AI worm self-propagation in a mainstream commercial productivity suite. The disclosure coordination period was 90 days, extended twice to 144 days total. Microsoft was provided with reproduction steps, videos, and proof-of-concept prompts. The researcher credited Microsoft product teams and MSRC for collaboration on technical analysis and mitigation.

Source

enklypesalt.com — Read original →