A security researcher has disclosed a self-propagating attack against Microsoft Copilot for Word that exploits how the AI assistant processes documents. The attack works by embedding invisible prompt injections directly into Word files. Each time a user interacts with Copilot while these documents are open, the hidden instructions execute automatically and infect newly created files with identical malicious prompts.

The vulnerability demonstrates a fundamental flaw in how Copilot handles document content. The AI treats all text in a file equally, whether visible or hidden, allowing attackers to manipulate the assistant's behavior without user awareness. Once infected, a document becomes a vector for further spread. Every time the file is reused or shared, Copilot unknowingly propagates the malicious instructions to additional files.

Microsoft acknowledged the issue but has not patched it after 144 days and two separate attempts at remediation. The researcher responsibly disclosed the vulnerability through Microsoft's official security reporting channels, yet the company's fixes failed to eliminate the core problem. This extended timeline raises questions about the company's ability to address AI-specific security issues that deviate from traditional software vulnerabilities.

The attack surface extends beyond individual users. In enterprise environments where files are shared across teams, the worm could spread across an organization's document ecosystem with minimal friction. An infected template or shared document could compromise workflows for dozens of employees simultaneously.

This vulnerability highlights a critical gap in how AI assistants validate input. Unlike traditional security threats that exploit code execution or system access, this attack manipulates the AI's instructions. As organizations integrate AI tools deeper into document workflows and business processes, the risk of prompt injection attacks grows proportionally. The 144-day lag between disclosure and failed fixes underscores that AI security expertise remains nascent within major software companies. Microsoft must address both the immediate technical flaw and the systemic gaps in how it approaches AI-specific vulnerabilities.