Microsoft 365 Copilot Word hidden-instruction prompt injection security flaw
Vulnerability
Summary
Hide ▲
Show ▼
Microsoft 365 Copilot for Word remains vulnerable to hidden-instruction prompt injection that can rewrite report figures and copy malicious instructions into the finished file. The attack reaches Copilot when a poisoned document enters context through an attachment or a OneDrive source selected by Work IQ. Microsoft confirmed the behavior and deployed mitigations, but the vulnerability class still reproduced at publication on GPT-5.6. The flaw is not zero-click, yet it still creates document-integrity risk for AI-assisted drafting and editing workflows.
Related Happenings
Cursor Windows repo-root git.exe code execution security flaw
Vulnerability
H score9
First: 15.07.2026 13:55
Last: 15.07.2026 13:55
Sources 1
About this happening:
Cursor on Windows automatically runs a repo-root git.exe when a repository is opened, creating arbitrary code execution as the logged-in user. The flaw affects cloned...
Cursor Windows repo-root git.exe code execution security flaw
VulnerabilityAbout this happening: Cursor on Windows automatically runs a repo-root git.exe when a repository is opened, creating arbitrary code execution as the logged-in user. The flaw affects cloned...
Microsoft Copilot remote code execution flaw (CVE-2026-48561)
Vulnerability
H score33
First: 14.07.2026 22:22
Last: 14.07.2026 22:22
Sources 1
About this happening:
A CVE-2026-48561 remote code execution flaw in Microsoft Copilot can let an unauthorized attacker execute code over the network, creating remote takeover risk for affected...
Microsoft Copilot remote code execution flaw (CVE-2026-48561)
VulnerabilityAbout this happening: A CVE-2026-48561 remote code execution flaw in Microsoft Copilot can let an unauthorized attacker execute code over the network, creating remote takeover risk for affected...
Prompt-injection proof-of-concept enables silent RCE in Claude Code and Codex
Technical Analysis
H score28
First: 10.07.2026 16:45
Last: 10.07.2026 16:45
Sources 1
About this happening:
Researchers demonstrated a proof-of-concept exploit that can force remote code execution in Anthropic’s Claude Code and OpenAI’s Codex, exposing a trust-boundary f...
Prompt-injection proof-of-concept enables silent RCE in Claude Code and Codex
Technical AnalysisAbout this happening: Researchers demonstrated a proof-of-concept exploit that can force remote code execution in Anthropic’s Claude Code and OpenAI’s Codex, exposing a trust-boundary f...
Microsoft 365 Copilot Enterprise SearchLeak remote code execution flaw (CVE-2026-42824)
Vulnerability
H score34
First: 15.06.2026 16:00
Last: 15.06.2026 16:00
Sources 1
About this happening:
Microsoft 365 Copilot Enterprise Search has a critical vulnerability chain, SearchLeak, that could let a user leak emails, calendar details, MFA codes, and indexed f...
Microsoft 365 Copilot Enterprise SearchLeak remote code execution flaw (CVE-2026-42824)
VulnerabilityAbout this happening: Microsoft 365 Copilot Enterprise Search has a critical vulnerability chain, SearchLeak, that could let a user leak emails, calendar details, MFA codes, and indexed f...
Windows Collaborative Translation Framework CTFMON improper link resolution EoP security flaw (CVE-2026-45586)
Vulnerability
H score20
First: 09.06.2026 20:57
Last: 09.06.2026 20:57
Sources 1
About this happening:
Windows Collaborative Translation Framework (CTFMON) has a local privilege-escalation vulnerability, CVE-2026-45586, that Microsoft patched in June 2026. An author...
Windows Collaborative Translation Framework CTFMON improper link resolution EoP security flaw (CVE-2026-45586)
VulnerabilityAbout this happening: Windows Collaborative Translation Framework (CTFMON) has a local privilege-escalation vulnerability, CVE-2026-45586, that Microsoft patched in June 2026. An author...
Timeline
-
30.07.2026 14:54 1 articles · 1h ago
Microsoft confirms Word prompt injection in Microsoft 365 Copilot and deploys mitigations
Mitigation Patch UpdateMicrosoft confirmed the Word prompt-injection behavior on March 31, 2026 and deployed two mitigations for Microsoft 365 Copilot: the first blocked the original prompt wording, and the second upgraded the underlying model to GPT-5.5.
Show sources
- Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents — thehackernews.com — 30.07.2026 14:54
-
30.07.2026 14:54 1 articles · 1h ago
Modified Word prompt injection still reproduces on GPT-5.6
Technical Analysis UpdateThe next day, modified instructions still reproduced on GPT-5.6, showing that the Word-based instruction chain could survive the March 31 mitigations when a malicious document entered Copilot's context again during another drafting or editing operation.
Show sources
- Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents — thehackernews.com — 30.07.2026 14:54
-
28.07.2026 03:00 2 articles · 2d ago
Håkon Måløy discloses Word prompt injection that rewrites Copilot drafts
Initial DisclosureHåkon Måløy disclosed on July 28, 2026 that hidden instructions in a Word document can make Microsoft 365 Copilot rewrite figures in a report and copy the same prompt into the output as white, eight-point text; he said the vulnerability class remained exploitable at publication and the chain was not zero-click.
Show sources
- Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents — thehackernews.com — 30.07.2026 14:54
- Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents — thehackernews.com — 30.07.2026 14:54