started · updated
Microsoft Copilot Word Worm Demonstrated by Security Researcher
Security researcher Håkon Måløy demonstrated a self‑propagating worm that exploits Microsoft 365 Copilot within Word documents. By embedding malicious instructions as white text on a white background, the worm leverages indirect prompt‑injection – a form of cross‑domain prompt injection – causing Copilot to execute hidden commands, modify the document (e.g., halving numbers in a report) and copy the same instructions into newly created files, thereby spreading without traditional malware such as macros.
Microsoft confirmed the behavior after a 144‑day collaboration with its Security Response Center. Initial mitigation attempts in early April were bypassed, and a comprehensive fix remains pending, highlighting a critical “context collapse” vulnerability where large language models cannot distinguish data from commands.
Entities
Håkon Måløy · Microsoft · Microsoft Copilot · Microsoft Security Response Center · Microsoft Word