← Back to blog

Microsoft Copilot for Word Vulnerability Exposes Hidden Prompt Injection Risk

A security researcher discovered that Microsoft Copilot for Word can inadvertently copy hidden prompts into new documents. This flaw could lead to unintended data exposure and manipulation in AI-assisted document workflows.

TL;DR

  • Hidden prompts in Word docs can be copied by Microsoft Copilot into new files
  • Researcher Håkon Måløy reported the issue 144 days before public disclosure
  • Proof of concept shows the behavior repeats in subsequent Copilot sessions
  • This creates potential for prompt injection attacks in document workflows
  • Organizations using Copilot should review document handling procedures

Microsoft Copilot for Word, part of the Microsoft 365 AI suite, has been found vulnerable to a prompt injection technique that can cause hidden instructions to persist in newly generated documents. Security researcher Håkon Måløy discovered that maliciously crafted prompts embedded in a document can influence Copilot's behavior and subsequently be copied into the AI-assisted output.

The vulnerability demonstrates how AI-powered document tools can inadvertently propagate hidden content, potentially leading to unauthorized data exposure or manipulation. Måløy reported the issue to Microsoft 144 days before making his findings public, following responsible disclosure practices.

Technical Details

  • Hidden instructions embedded in Word documents can trigger Copilot to rewrite content in specific ways
  • Copilot then copies these same hidden instructions into the final generated document
  • The internally created files maintain the problematic behavior when used in subsequent Copilot sessions
  • This creates a persistent risk across multiple document generations
  • The vulnerability represents a form of prompt injection attack specific to AI document tools

Security Implications

  • Organizations may unknowingly share documents containing hidden prompts
  • AI-assisted document workflows could propagate malicious instructions
  • Sensitive information might be exposed through manipulated document content
  • Users should exercise caution when sharing AI-generated documents from Copilot
  • Security teams need to evaluate AI tool integration risks in their document processes

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

Microsoft Copilot for Word Vulnerability Exposes Hidden Prompt Injection Risk — Agent Breach Blog | Agent Breach