研究人员公开披露了Microsoft Copilot for Word的一个严重安全漏洞,攻击者可利用该漏洞创建自传播的AI蠕虫[1]。攻击者通过在文档中嵌入隐藏的白色文字恶意指令(以JSON格式编写)实施攻击,Copilot在处理该文档时会剥除文本格式,使隐藏的指令对AI模型仍保持可读[1]。当用户将包含恶意指令的文档作为源材料,使用Copilot起草或编辑新文档时,恶意指令会被触发并自动将完整攻击提示词复制到新生成文档的底部(同样以白色8号字体隐藏),使新文档成为新的攻击向量,从而实现自传播[1]。
该漏洞在威胁模型上具有特别的危害性,因为攻击者无需获得受害者Microsoft 365租户的访问权限,仅需通过SharePoint、Teams或Outlook等常用协作工具共享恶意文档即可发起攻击[1]。研究人员于2026年3月6日初次报告该漏洞,经过144天的协调披露期后于2026年7月28日公开[1]。尽管Microsoft已部署多项修复措施(包括升级至GPT-5.5),但使用修改后的提示词仍可绕过所有现有的缓解手段,该漏洞类别持续可被利用[1]。研究人员建议用户将来自外部的文档视为不受信任来源,使用前应进行审查,并在分享或分发Copilot生成的文档前进行谨慎评估[1]。
Researchers have identified a critical security vulnerability in Microsoft Copilot for Word that enables self-propagating artificial intelligence worms through infected documents [1]. Attackers can embed hidden malicious instructions in files by using white text formatted as JSON prompts, which Copilot strips of formatting while keeping the content readable to the AI model [1]. When users reference the compromised document as source material to draft or edit new content using Copilot, the malicious instructions are triggered and automatically replicate themselves into the newly generated documents by appending the full attack prompt in white text at 8-point font size [1].
The vulnerability poses a significant threat because attackers need not gain access to a victim's Microsoft 365 tenant; they can simply distribute the malicious document through SharePoint, Teams, Outlook, or other sharing mechanisms to initiate the propagation chain [1]. Although Microsoft has deployed multiple remediation efforts, including an upgrade to GPT-5.5, modified versions of the malicious prompt can circumvent all existing mitigation measures, and the underlying vulnerability class remains exploitable [1]. The researchers disclosed their findings through a coordinated process, initially reporting the issue on March 6, 2026, followed by a 144-day coordination period before public disclosure on July 28, 2026 [1].
Researchers recommend treating external documents as untrusted sources, reviewing attached files before use, and carefully evaluating Copilot-generated documents before sharing or distributing them further [1].