Researchers Discover Self-Propagating AI Worms in Microsoft Copilot for Word
Key Takeaways
- ▸Document-borne AI-worms can self-propagate through Copilot for Word by embedding hidden prompt injection attacks that get copied into newly generated documents
- ▸The attack exploits normal business workflows—document reuse and collaboration—enabling silent propagation without continued attacker involvement
- ▸Attack scenarios include manipulation of sensitive documents like financial reports that cascade through organizations as downstream users reuse infected documents
Summary
Security researcher Canopy9560 has disclosed a significant vulnerability in Microsoft Copilot for Word that enables document-borne AI-worms to self-propagate through normal productivity workflows. The attack exploits Cross-Domain Prompt Injection Attacks (XPIAs) by embedding hidden malicious instructions in documents that are later used as source material with Copilot. When a user includes a compromised document while drafting or editing, the AI interprets the hidden instructions as legitimate requests, alters the generated document, and critically, copies these malicious instructions into the resulting document, turning it into a new attack carrier.
This creates a self-sustaining propagation chain: compromised documents can infect downstream documents used by different users in subsequent Copilot-assisted workflows, without requiring the original malicious document or attacker's involvement. An illustrative scenario shows an employee downloading market analysis from a compromised website, using it with Copilot to draft a financial report that gets altered and infected, then sharing the report internally where colleagues reuse it for further reports—propagating the attack silently through the organization.
The vulnerability was disclosed through a 144-day coordinated disclosure process with Microsoft's Security Response Center (MSRC). At the time of publication, no full customer-side remediation was available; Microsoft advised treating external documents as untrusted and carefully reviewing Copilot-generated content before sharing. This represents among the first public demonstrations of self-replicating AI-worms in mainstream commercial productivity suites.
- Disclosed through coordinated 144-day MSRC process; no full remediation available at publication, only defensive mitigation practices like treating external documents as untrusted
Editorial Opinion
This discovery reveals a critical vulnerability in AI-assisted productivity workflows: as generative AI embeds deeper into document creation and editing, attackers can weaponize trusted document workflows to propagate malicious instructions without user awareness. Unlike traditional malware requiring active exploitation, these AI-worms spread through normal business practices—document reuse and collaboration—making them uniquely insidious. The finding underscores the urgent need for AI systems to better validate and sanitize external inputs, and for organizations to fundamentally rethink trust models when integrating AI assistants into document workflows.



