New Prompt Injection Worm Targets Microsoft Word Copilot
New Vulnerability: Self-Replicating Worm in Microsoft Word via Copilot
FAQ
What is the AI worm in Word?
It is a prompt injection attack that hides malicious instructions in a Word document. When Copilot is used to edit the document, the instructions are executed and copied to new documents, causing automatic spread like a worm.
How does this attack affect MENA enterprises?
Enterprises relying on Copilot in Word may face data theft or document manipulation without knowledge, requiring enhanced cybersecurity measures.
Has Microsoft fixed the vulnerability?
Responsible disclosure was made 144 days ago, but no comprehensive patch covering all attack vectors has been released yet.
What preventive measures are recommended?
Educate employees about untrusted documents, restrict Copilot usage with external sources, and monitor suspicious document behavior.
Source: Simon Willison (LLM & tools)
AI-assisted content, human-reviewed.