Håkon Måløy has demonstrated a new method for prompt injection that allows attackers to turn Microsoft Word documents into self-replicating worms. The technique involves embedding hidden instructions within a file intended for use as source material in Copilot for Word. The AI assistant interprets these concealed commands as part of the user’s request and alters the document accordingly. Crucially, Copilot then copies these hidden instructions into the resulting output file. When that new document is later used in another Copilot-assisted workflow, the instructions trigger again and propagate further without the original malicious file being present.
This approach differs from previous instances of hidden white-on-white text because it deliberately replicates the payload itself. While Microsoft received responsible disclosure of the flaw fourteen months ago, no complete mitigation currently exists for this class of attack. The issue highlights a specific vulnerability in how generative AI tools process and rewrite content during collaborative workflows.
* The attack chain requires the initial document to be used as input for Copilot for Word.
* Microsoft has not released a full fix despite the long disclosure window.
* Propagation occurs automatically when the infected document enters another AI workflow.


