Security researcher Hakon Maloy discovered a vulnerability in Microsoft 365 Copilot that enables the creation of a self-propagating AI worm. This flaw utilizes prompt-injection attacks to leak confidential company data and spread across organizational networks.
The attack begins when a user opens a Word document containing hidden malicious commands. Copilot executes these commands to exfiltrate data and embeds the worm into new documents created by the user.
The infection spreads virally as users share these compromised documents without further action from the attacker. Microsoft has addressed related vulnerabilities, but this specific AI worm flaw in Microsoft Word remains exploitable.