Microsoft Copilot for Word has been found vulnerable to a new class of attacks known as Cross-Domain Prompt Injection (XPIA), which allows malicious instructions to effectively "reproduce" within a company's document workflow. Researchers have identified a mechanism for creating an "AI worm": an attacker hides instructions in a single file, and as Copilot processes it, the AI doesn't just execute the commands—it embeds them into new documents. This triggers a chain reaction as employees use infected reports as templates for new drafts, spreading the infection across the internal network without further hacker intervention.

Discovered after lengthy disputes with the Microsoft Security Response Center (MSRC), the vulnerability's mechanics blur the line between suspicious external data and trusted internal drafts. The scenario is straightforward: an employee downloads a market analysis containing a hidden payload and asks Copilot to help draft a financial report. The AI dutifully distorts the figures and weaves the malicious prompt into the final file. When a colleague uses that report to prepare their own document, the worm reactivates. Consequently, the AI assistant transforms into the perfect insider, quietly compromising the integrity of corporate data.

Attacker-controlled instructions are copied from one document into files created or edited via Copilot, turning them into new carriers for the attack.

This is more than just a curious bug; it represents a serious escalation. The industry has moved from simple prompt manipulation to self-sustaining infections within office suites. Unlike the well-known Morris II worm, which targeted email agent ecosystems, this discovery strikes at the heart of corporate operations—shared documents. It is becoming increasingly clear that the industry has yet to find a way to safely merge Large Language Models with traditional productivity software.

The 144-day disclosure failure

The timeline of this case raises questions about Microsoft's readiness for a transparent dialogue on security. Researchers provided full reproduction steps and proof-of-concept (PoC) scripts within the standard 90-day disclosure window. However, Microsoft extended the deadline twice, ultimately sitting on the report for 144 days before publication. For businesses already integrating AI into their workflows, this is a clear signal: the defensive perimeter surrounding LLMs currently exists primarily in marketing presentations.

Risks for autonomous infrastructure

This vulnerability threatens the transition to AI agents that are expected to perform actions rather than just write text. If an AI worm can hop from an external document into a confidential internal report, the potential damage is massive. The distribution mechanism is hard-wired into standard business processes. Until a structural solution is found, this "perfect insider" remains embedded in the word processor, waiting for a user to cite the next "infected" file.

Microsoft's sluggishness in patching fundamental flaws suggests that using Copilot in closed environments may be premature. IT directors should re-evaluate trust policies for generative content before granting AI agents actual authority over infrastructure. Otherwise, automation risks becoming automated espionage, where gaining access requires no password cracking—just sending a victim a "helpful" file.

CybersecurityGenerative AIAI SafetyMicrosoftAI Agents