Theregister
Microsoft Word Copilot Vulnerability Enables Self-Propagating AI Worms
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A vulnerability in Microsoft Copilot for Word allows hidden prompts in documents to create self-propagating AI worms that can tamper with business content. Researcher Håkon Måløy disclosed the issue after months of coordination with Microsoft, revealing that no robust mitigation is currently available. The attack vector involves malicious instructions embedded in documents that alter outputs and replicate themselves across new files. This vulnerability affects users of Microsoft 365, as the attacker only needs to share a compromised document. Måløy's research indicates that the worm can spread without further involvement from the attacker after initial infection. The issue has been publicly disclosed after 144 days of testing and attempts at mitigation, which have proven ineffective.
Key Points: • A new vulnerability in Microsoft Copilot for Word allows self-propagating AI worms. • Malicious instructions in documents can alter outputs and replicate across new files. • No robust mitigation has been achieved despite months of coordination with Microsoft.