Microsoft Confirms AI Worm Spreading Through Copilot and Word

Microsoft has confirmed a security vulnerability involving an AI worm that propagates through productivity applications like Word and Copilot. Discovered by Norwegian AI researcher Håkon Måløy, the exploit uses indirect prompt injection to conceal malicious instructions in source documents, allowing the payload to self-replicate across standard enterprise workflows.

The Architecture of an AI-Driven Vector

The core mechanism relies on the fundamental inability of current Large Language Models (LLMs) to reliably distinguish between user-provided data and executable instructions. When Copilot processes an infected source file—such as a financial report or corporate contract—it treats the embedded malicious instructions as valid commands. These instructions can then alter figures within the document and rewrite themselves into the newly generated output.

As Aman Mahapatra, chief strategy officer for Tribeca Softtech, noted of the vulnerability, it completely sidesteps conventional defense-in-depth security controls. Because the document arrives looking entirely legitimate, it bypasses standard email security gateways. Endpoint protection tools fail to trigger because no native binary code executes; instead, the AI service simply follows the injected semantic instructions. Finally, data loss prevention (DLP) controls are bypassed because the exfiltration occurs natively through the user’s authenticated session.

The issue shares a clear conceptual lineage with classical software vulnerabilities. Flavio Villanustre, CISO for the LexisNexis Risk Solutions Group, compared the flaw to early SQL injection vulnerabilities. Decades ago, databases struggled to separate data from query commands until parameterized binding was introduced. According to Mike Leone, a VP and principal analyst at Moor Insights & Strategy, thirty years later the software industry has built an entire category of LLM-driven applications that still fail to maintain that boundary.

Coordinated Disclosure and Microsoft’s Mitigations

Håkon Måløy began working with the Microsoft Security Response Center (MSRC) on March 3, leading to multiple small, focused mitigations distributed across the platform. While these tweaks successfully reduced the demonstrated attack surface and limited the reach of potential exploits, the foundational vulnerability remains active.

Microsoft addressed the findings in an official statement, emphasizing a defense-in-depth strategy. “We have addressed the findings reported by the researcher and thank them for working with us through coordinated vulnerability disclosure. To address this class of risk, we use a defense-in-depth strategy with safeguards that block malicious instructions at multiple points and help keep tasks aligned with users’ requests,” the company stated via email. Microsoft encourages enterprise customers to install the latest updates, treat external content with caution, and review all AI-generated content before sharing.

Industry analysts remain divided on how the market should respond. Frank Dickson, group VP for security at IDC, argued that a definitive architectural fix requires industry-wide agreement to separate instructions from data at the model or platform level, which he considers a multi-year research problem. Conversely, Mike Leone argued that Microsoft can independently harden its own product ecosystem, noting that customers benefit immediately if Copilot’s document path is secured.

Immediate Enterprise Mitigation Strategies

While long-term solutions are debated at the model layer, security leaders must address active enterprise risks today. Experts suggest several operational safeguards to contain document-borne injection attacks:

AI Worm in Microsoft Copilot? Hidden Prompts Can Infect Word Documents | Prompt Injection Explained
  • Disable or restrict Copilot’s auto-discovery behavior to prevent the automated pulling of untrusted external files into active sessions.
  • Require humans to explicitly select and authorize any source documents fed into AI workflows.
  • Implement strict visual diffs or redlines for any changes made by Copilot to financial or consequential documents, mandating manual human approval before saving.
  • Track provenance metadata within documents to log which files were touched or generated by AI systems, allowing security teams to audit propagation chains.

Despite the severe implications for enterprise supply chains—where contracts, policies, and partner documents could inherit malicious behavior while retaining trusted metadata—some analysts urge caution against panic. Tyler Reguly, Fortra’s associate director of security R&D, noted that the attack still requires specific conditions, such as a user downloading an external Word document containing hidden white-text prompts, making it resemble a complex laboratory scenario rather than an immediate mass epidemic.

Photo of author

Sophie Lin - Technology Editor

Sophie is a tech innovator and acclaimed tech writer recognized by the Online News Association. She translates the fast-paced world of technology, AI, and digital trends into compelling stories for readers of all backgrounds.

Asian Football Confederation Opposes Controversial FIFA Proposals Alongside UEFA and Concacaf

Malaysian Airlines Pilot Arrested in Jakarta with 70,000 Ecstasy Pills After Positive Drug Test

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.