Article 77AQ4 Word worm crawls into Copilot, spreads chaos

Word worm crawls into Copilot, spreads chaos

by
from www.theregister.com - Articles on (#77AQ4)
Story ImageUPDATED Watch out for untrusted documents. According to research, an attacker can hide malicious instructions in a Word document that, when included in Copilot for Word's context, may alter document output and copy the instructions into newly created files that use the affected document as source material, without the victim noticing. Hakon Maloy, a Norwegian data scientist with a PhD in applied AI and ML, publicly disclosed the issue in a blog post Tuesday. Maloy describes the issue in considerable detail while withholding the specific prompt payload, arguing that, because no robust mitigation exists, it would be irresponsible to disclose anything beyond the class of the vulnerability. To my knowledge, this is among the first public demonstrations of document-borne AI-worm self-propagation through normal workflows in a mainstream commercial productivity suite," Maloy noted. Maloy said that he has been working with Microsoft since March 2026 on addressing the vulnerability, but after multiple updates to Copilot, this new class of Copilot worm is still viable. Microsoft mitigated the exploit demonstrated by his original proof-of-concept prompt, but Maloy said rewording the payload allowed him to successfully propagate the worm and alter financial data in a target document. Maloy and Microsoft twice delayed public disclosure of the issue, but, after 144 days, he said in his report that people needed to be made aware. The coordination period agreed with Microsoft has been exhausted, and testing shows that no robust mitigation for the broader vulnerability class is currently available," Maloy wrote. Two mitigation attempts, including a model upgrade, did not close the class." How Copilot propagates a Word worm Maloy explained the worm's execution with an example involving an employee preparing a financial report for their company. The employee downloads a market analysis from a trusted website to help with the preparation of a financial report in Copilot, unaware that the source had been compromised and the document they downloaded contains hidden malicious instructions. The hidden instructions (inserted as small white text in his proof of concept) tell Copilot to alter figures in the report the employee generates and to copy the worm into the report they create with Copilot. If another employee later adds that report to their own work, the whole process begins again, and documents generated from it also contain the worm, and, as it spreads, it makes tracing the infection to its source extremely difficult. The attack can therefore continue without further involvement from either the compromised website or the original malicious document," Maloy said. The attacker does not need access to the victim's Microsoft 365 tenant. The attacker only needs to share a malicious document with the victim." Copilot should use information in documents a user includes in its context for a project without treating instructions embedded in a document as additional prompts, Maloy said, but his research suggests it doesn't always do that. A fundamental flaw Maloy argues that he's essentially dug up a new type of cross-domain prompt injection attack that abuses a fundamental part of modern LLM architecture. For AI-assistants to be useful, they often must process emails, documents, webpages, memories, tool outputs, and other information that may be controlled by an attacker," the researcher said. But if an LLM has to process data in order to determine it contains an attack, the attack could already be influencing that determination. Relying on the model to detect XPIAs therefore resembles asking an interpreter to execute an untrusted program to determine whether that program is safe to execute," Maloy asserted. Were Microsoft or some other company to pop another model in front of that model to check for malicious content, it only moves the problem outward, Maloy said, creating a LLMs all the way down" scenario. The long-term challenge likely lies in designing systems in which goals and intentions also exist independently of the information being processed," he said. Until that time, Maloy argues, any system that integrates an LLM into a trusted workflow today must assume that attacker-controlled content entering the model's context will result in compromise at some rate." What can Copilot customers do to reduce the risk? Short of ditching Copilot, there's not much. No customer-side remediation fully addresses the issue at the time of publication," Maloy said, but he does have a few tips. Treat externally sourced documents as untrusted when using them in Copilot, he recommends, and fully review every single document before sending it to Copilot, and fully review any Copilot-generated or edited documents before distributing them. Sheesh - if you're going to have to actually read that stuff, you might as well just cut Copilot out of the loop and do the thinking yourself. Microsoft has been in touch to confirm the research, but the company's statement doesn't do anything to allay fears this is an unsolved issue. We have addressed the findings reported by the researcher and thank them for working with us through coordinated vulnerability disclosure. To address this class of risk, we use a defense-in-depth strategy with safeguards that block malicious instructions at multiple points and help keep tasks aligned with users' requests. We are continuously strengthening these safeguards as the technology and threat landscape evolve. We encourage customers to install the latest updates, use multiple layers of security protection, treat content from unknown sources with caution, and review AI-generated content before using or sharing it." We also reached out to Maloy, but didn't hear back before publication. (R) Updated at 1841 GMT on July 29 to add Microsoft's statement.
External Content
Source RSS or Atom Feed
Feed Location http://www.theregister.co.uk/headlines.atom
Feed Title www.theregister.com - Articles
Feed Link https://www.theregister.com/
Reply 0 comments