Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

A New Vulnerability Exposed: Microsoft Copilot for Word's Hidden Prompts and the Rise of Prompt Injection Attacks



A recent vulnerability in Microsoft 365's Copilot tool has been exposed, allowing malicious actors to inject hidden instructions within Word documents. This vulnerability can be exploited by attackers to manipulate the output of Copilot, leading to potential security breaches.

  • MICROSOFT COPILOT VULNERABLE TO PROMPT INJECTION ATTACKS
  • Malicious actors can inject hidden instructions in Word documents to manipulate Copilot's output, leading to potential security breaches.
  • MALICIOUS DOCUMENTS CAN BE CRAFTED TO EXPLOIT THIS VULNERABILITY, ALLOWING ATTACKERS TO MAINTAIN ATTACK CHAINS WITHOUT LEAVING TRACES
  • MICROSOFT HAS DEPLOYED MITIGATIONS BUT THEY DO NOT FULLY ADDRESS THE ISSUE, AND THE VULNERABILITY REMAINS EXPLOITABLE
  • PROMPT INJECTION ATTACKS WORK BY MISTAKING INSTRUCTIONS INSIDE DOCUMENTS FOR PART OF THE USER'S REQUEST, ALLOWING COPILOT TO EXECUTE MALICIOUS CODE
  • ORGANIZATIONS MUST RE-EVALUATE THEIR APPROACH TO SECURING MICROSOFFT 365 COPILOT AND OTHER SIMILAR TOOLS BY EDUCATING EMPLOYEES AND IMPLEMENTING ROBUST SECURITY MEASURES



  • Microsoft Copilot, a powerful tool integrated into Microsoft 365, has recently been discovered to be vulnerable to prompt injection attacks. This vulnerability allows malicious actors to inject hidden instructions within a Word document, which can then be used to manipulate the output of Microsoft Copilot, leading to potential security breaches.

    The discovery was made by Håkon Måløy, who reported the issue to Microsoft 144 days prior to its official disclosure. In his proof of concept, Måløy demonstrated how malicious documents could be crafted to exploit this vulnerability. He also showed that once a document with these instructions is generated by Copilot, it can be used in subsequent sessions without leaving any trace, making it difficult for security experts to track the origin of the attack.

    In response to this vulnerability, Microsoft deployed two mitigations: one blocked the original prompt wording and another upgraded the underlying model to GPT-5.5. However, as Måløy pointed out, these measures do not fully address the issue, and the vulnerability class remains exploitable at present.

    To understand how this vulnerability works, it's essential to delve into the inner workings of Microsoft Copilot for Word. When a user starts a drafting or editing operation with Copilot, the tool searches through various files and sources to decide what belongs in the draft. In doing so, it can mistake instructions inside documents for part of the user's request. This is achieved by Word stripping color and font size before sending document text to the large language model, leaving white-on-white instructions legible to the model.

    Måløy used this vulnerability to his advantage. He crafted a malicious document that contained a payload altered by one part, which told Copilot to copy and conceal these commands, framing them as source-tracking requirements. The other part of the payload altered the document itself, halving every financial figure and copying the full prompt into the output in white, eight-point text.

    When Måløy used this malicious document with Copilot, he was able to reproduce the same behavior even after removing it from its original context. He could then create an ordinary internally generated document that triggered the same behavior when used in a second drafting session. This demonstrates how easily the attack chain can be maintained and repeated without leaving any trace of the initial source.

    Microsoft 365 Copilot's security measures have been enhanced to include jailbreak and cross-prompt injection attack (XPIA) classifiers, which are intended to block high-risk prompts. Additionally, Defender for Office 365 includes mail-flow inspection for inbound email, aiming to cover injected instructions from grounded content. However, it remains unclear whether these safeguards effectively detect the exact payload used in this vulnerability.

    The disclosure highlights a critical issue with prompt injection attacks and emphasizes the need for improved security measures in AI models like Microsoft Copilot. As Måløy pointed out, no customer-side remediation fully addresses the issue because payload-specific blocks do not reach the class — a model must process attacker-controlled content to decide whether it is malicious.

    Furthermore, Microsoft has recognized that prompting alone is not a reliable security boundary. Instead, they advocate for memory access and isolation controls by deterministic systems rather than model instructions. This shift in focus underscores the urgent need for robust AI security solutions as these models become increasingly pervasive across various industries.

    In light of this vulnerability, organizations must re-evaluate their approach to securing Microsoft 365 Copilot and other similar tools. By adopting a proactive strategy that includes educating employees about prompt injection attacks and implementing robust security measures, companies can significantly reduce the risk associated with relying on AI-powered drafting and editing tools.

    To better safeguard against software vulnerabilities discovered by AI models, organizations must develop strategies that address these emerging risks proactively. This involves staying informed about the latest discoveries and vulnerabilities and being prepared to implement necessary security patches and updates in a timely manner.

    Ultimately, this vulnerability serves as a stark reminder of the potential dangers lurking within seemingly powerful AI tools like Microsoft Copilot for Word. As these models continue to evolve and improve their capabilities, it is crucial that developers, users, and organizations prioritize robust AI security measures to protect against prompt injection attacks and other emerging threats.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/A-New-Vulnerability-Exposed-Microsoft-Copilot-for-Words-Hidden-Prompts-and-the-Rise-of-Prompt-Injection-Attacks-ehn.shtml

  • https://thehackernews.com/2026/07/microsoft-copilot-for-word-can-copy.html


  • Published: Thu Jul 30 08:46:57 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us