A cybersecurity researcher has demonstrated a novel exploit dubbed a 'Word worm' that can infiltrate and spread through Microsoft Copilot. The vulnerability leverages the AI's ability to process and summarize documents, allowing malicious instructions hidden within a Word file to compromise the assistant's behavior.
A Persistent Threat
Despite months of coordinated disclosure and communication with Microsoft, the researcher claims that a robust mitigation strategy has yet to be implemented. The exploit functions by embedding 'indirect prompt injection' attacks that trigger when Copilot analyzes the infected document, potentially leading to data exfiltration or the spreading of the malicious prompt to other users and documents.
The discovery highlights a growing class of security risks inherent in Large Language Model (LLM) integrations, where traditional file-scanning techniques may fail to detect adversarial prompts designed to manipulate AI logic.








