Brief IA

Microsoft Word: AI Copilot Exploited for Attacks

🛠️ AI Tools·Tom Levy·

Microsoft Word: AI Copilot Exploited for Attacks

Microsoft Word: AI Copilot Exploited for Attacks
Key Takeaways
1A new prompt injection attack targets Microsoft Word via Copilot, discovered by Håkon Måløy.
2This attack allows for the creation of self-replicating worms, spreading hidden instructions within documents.
3Microsoft was informed 144 days ago, but no complete solution is available yet.
💡Why it mattersThis vulnerability exposes Word users to increased security risks, potentially compromising the integrity of documents.
Le brief IA que lisent les pros

Le brief IA que les pros lisent chaque soir

Les 7 actus IA du jour, décryptées en 5 min. Gratuit.

Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.

Choisis ton rythme

Gratuit · Pas de spam · Désabonnement en 1 clic

📄
Full Analysis

A New Vulnerability in Microsoft Word

Håkon Måløy has recently uncovered a new attack method involving prompt injection targeting Microsoft Word. This innovative technique transforms attacks into self-replicating worms, thereby increasing their potential for propagation.

The attack involves inserting hidden instructions into a Word document, which is then used as source material by Copilot for Word. The latter can interpret these instructions as part of the user's request, which can manipulate the document being drafted or edited. Furthermore, Copilot can copy these hidden instructions into the resulting document, turning it into a new propagation vector.

A Concerning Propagation Vector

If this new vector is used in another workflow assisted by Copilot, the instructions can trigger again and spread to other documents, even in the absence of the original document from the attacker. This ability to self-replicate is a first in the realm of prompt injection attacks.

Microsoft's Response

The vulnerability was responsibly reported to Microsoft, which had 144 days to develop a fix. However, no comprehensive solution has yet been implemented to cover the entirety of this class of attacks. This situation leaves Word users exposed to potentially serious security risks.

Brief IA — L'actualité IA en français

L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.