Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents

Recent findings have revealed a significant vulnerability in Microsoft 365 Copilot for Word, allowing hidden instructions embedded in documents to be inadvertently copied into new drafts. This issue, disclosed by cybersecurity researcher Håkon Måløy, raises critical concerns for enterprise security, particularly regarding document integrity and data leakage.

Technical Analysis

The vulnerability revolves around the way Microsoft 365 Copilot interacts with document content. Specifically, it can misinterpret hidden instructions as part of a user's request during the drafting process. Måløy's proof of concept demonstrated that when a document containing these hidden prompts is used, Copilot can rewrite figures and copy the same instructions into the final output without user awareness.

Initially reported to Microsoft on March 31, the issue was confirmed, leading to two mitigations: blocking the original prompt wording and upgrading the underlying model to GPT-5.5. However, the vulnerability persisted even after these updates, as Måløy noted that modified instructions continued to exploit the flaw with GPT-5.6.

Affected Systems

This vulnerability primarily affects Microsoft 365 users who utilize the Copilot feature in Word. Given the widespread adoption of Microsoft 365 in enterprise environments, the implications of this vulnerability could impact a significant number of organizations globally.

Attack Method / Threat Activity

The attack is not a zero-click exploit; it requires user interaction with Copilot during drafting or editing sessions. Malicious documents must be introduced into the model's context, either as attachments or sourced from OneDrive. In Måløy's demonstration, Copilot halved financial figures and embedded hidden prompts in white text, rendering them invisible to users but still legible to the model.

Each instance of exploitation necessitates a new drafting or editing operation, meaning that the vulnerability does not propagate automatically. Instead, it relies on the user to engage with the Copilot feature repeatedly.

Detection Opportunities

📬 Stay ahead of the threat

Get the latest SOC guides, threat intel, and detection engineering — straight to your inbox.

To detect potential exploitation of this vulnerability, organizations should implement the following strategies:

  • SIEM Integration: Utilize Security Information and Event Management (SIEM) systems to monitor document creation and editing activities involving Copilot.
  • Threat Hunting: Conduct regular threat hunting exercises focused on document metadata and hidden content within Word files.
  • Behavioral Analysis: Analyze user interactions with Copilot to identify unusual patterns, such as unexpected changes in document figures or content.

Mitigation Recommendations

Organizations can adopt several measures to mitigate the risks associated with this vulnerability:

  • Document Review: Treat all external documents as untrusted. Review attached documents thoroughly before using them with Copilot.
  • Training and Awareness: Educate employees about the risks of hidden instructions in documents and encourage them to verify outputs generated by Copilot.
  • Access Controls: Implement strict access controls for sensitive documents to limit exposure to potentially malicious content.

Business Impact

The implications of this vulnerability extend beyond technical concerns. Organizations may face risks related to data integrity, compliance violations, and reputational damage if sensitive information is inadvertently altered or leaked. Furthermore, the potential for financial inaccuracies in reports could lead to significant business decisions being made based on flawed data.

Final Summary

The vulnerability in Microsoft 365 Copilot for Word highlights the importance of vigilance in document security. As organizations increasingly rely on AI-driven tools for productivity, understanding and mitigating risks associated with these technologies is crucial. By implementing robust detection strategies and fostering a culture of security awareness, enterprises can better protect themselves against the potential exploitation of such vulnerabilities.