Announcements
We ıntegrate ınformatıon ın lıfe

  • DOLAR
  • EURO
  • ALTIN
  • BIST
Security Vulnerability in Microsoft Word: Copilot at Risk

Security Vulnerability in Microsoft Word: Copilot at Risk

Commands hidden in Microsoft Word documents threaten Copilot. Here is the security vulnerability that allows Copilot to silently modify documents.

A security researcher has discovered that commands hidden within Microsoft Word documents create a significant security vulnerability in Microsoft 365 Copilot. Documents created in this way cause Copilot to silently modify content and copy malicious commands into newly created documents.

This technique, discovered by data scientist Håkon Måløy, is based on a security vulnerability called cross-field command injection (XPIA). Attackers can insert instructions into Word documents by adding white text on a white background, instructions that users don’t see but the AI ​​model reads.

Risk of Systemic Spread

The most striking aspect of this type of attack is its ability to self-replicate and spread. Copilot detects these implicit commands when drafting or editing a document and transfers them to a new document, thus making each new document a carrier.

The attack can be triggered when a user manually uploads a document to Copilot or when Copilot performs an automatic search on OneDrive. In Måløy’s tests, it was observed that Copilot halved the numbers in financial reports and then secretly added these commands to the new document.

Although Microsoft released two different fixes within a 144-day disclosure period, the researcher states that this vulnerability has still not been closed. The first fix was made in April with the update of the “Edit with Copilot” experience, while the second occurred in July with the upgrade of the model to GPT-5.5.

In both cases, Måløy managed to reproduce the attack using different command structures. Microsoft states that they are trying to prevent these types of risks with their depth of defense strategy and that they are constantly updating their security measures.

Things to consider for security

This type of attack highlights a fundamental problem in how AI assistants process untrusted content. The model is essentially influenced by the content before it assesses whether the content is harmful.

Måløy emphasizes that users should be careful when using external documents with Copilot. Furthermore, it is strongly recommended that AI-generated content be reviewed before being shared.

The researcher argues that generated documents should have a metadata system that records the source material and any edits made. This system, even if it doesn’t prevent the attack, could make it possible to trace the infection.

In a future where Copilot can perform more autonomous processes, the impact of these types of vulnerabilities on workflows could increase even further. Microsoft always advises its users to install the latest updates and to be cautious about content from unknown sources.

Do you think AI tools can provide complete defense against this type of command injection?

Social Media Share:

TOGETHER FOR A LOOK

Can you share with us your comment?