Microsoft 365 Copilot Vulnerability Exposed
A security researcher has disclosed a vulnerability in Microsoft 365 Copilot, allowing attackers to silently alter documents and spread malware through internal workflows. The attack, known as cross-domain prompt injection, was reproducible despite Microsoft's two mitigations over a 144-day disclosure period.
Key points
- A security researcher, Håkon Måløy, discovered a vulnerability in Microsoft 365 Copilot that allows attackers to alter documents and spread malware.
- The attack, known as cross-domain prompt injection (XPIA), involves hiding instructions in a Word document that are then executed by Copilot.
- Microsoft shipped two mitigations over a 144-day disclosure period, but the attack remains reproducible.
- The vulnerability affects internal workflows, allowing the malicious file to spread without the original file and without macros, malware, or code execution.
- Microsoft has not yet released a robust fix for the broader vulnerability class.
Microsoft 365 Copilot Vulnerability Exposed
A security researcher has disclosed a vulnerability in Microsoft 365 Copilot, a powerful AI-powered writing tool. The vulnerability, known as cross-domain prompt injection (XPIA), allows attackers to silently alter documents and spread malware through internal workflows.
The attack, discovered by Håkon Måløy, a data scientist with a doctorate in applied machine learning, involves hiding instructions in a Word document that are then executed by Copilot. This allows the malicious file to spread without the original file and without macros, malware, or code execution.
Microsoft shipped two mitigations over a 144-day disclosure period, but the attack remains reproducible. The vulnerability affects internal workflows, making it a significant concern for organizations that use Copilot.
Microsoft has not yet released a robust fix for the broader vulnerability class, leaving organizations vulnerable to this type of attack. It is essential for users to be aware of this vulnerability and take necessary precautions to protect themselves.
Sources
The WireByte editorial team synthesises technology news from multiple primary sources, verifies the facts, and links every source. Articles are produced with AI assistance and reviewed under our editorial policy.