Wiki · news-analysis · confidence: high · ⚙ auto-approved · fact-checker

AI worm ใน Copilot for Word: หนึ่งใน demonstration แรกของ prompt injection ที่ทำสำเนาตัวเองผ่านเอกสารใน productivity suite เชิงพาณิชย์

prompt-injectionagent-securitymicrosoft-copilotm365xpiaresponsible-disclosureupdated 2026-07-30

AI worm ใน Copilot for Word (เผยแพร่ 28 ก.ค. 2026)

สถานะข้อมูล ณ 30 ก.ค. 2026 · หมวดนี้เน่าเร็ว: คำว่า "ยัง exploit ได้" ผูกกับรุ่นโมเดล (GPT-5.5/5.6) และ mitigation ที่ Microsoft ทยอย deploy · ต้อง re-check ภายใน 30 วัน ไม่ใช่ 60 อ่านคู่กับ gitlost-github-agent-injection · claude-web-fetch-exfiltration · cursor-ide-rce-2026 · ms-copilot-cowork

เรื่องย่อ

Håkon Måløy เผยแพร่งาน "Context Collapse, Part 3 - AI Worming through Word" เมื่อ 28 ก.ค. 2026 แสดง prompt injection ใน Copilot for Word ที่ทำสำเนาคำสั่งของตัวเองต่อไปในเอกสารที่ Copilot สร้างขึ้นใหม่ จนแพร่ต่อได้เองในองค์กร (enklypesalt · The Register ยืนยันวันเผยแพร่ว่าเป็นวันอังคารที่ 28 ก.ค. ในบทความวันที่ 29 ก.ค.)

⚠ ข้อความที่ต้องพูดให้ถูกและเราเกือบเขียนผิดเอง: นี่ไม่ใช่ "ตัวแรกของโลก" ผู้เขียนเอง hedge สามชั้นว่า "To my knowledge, this is among the first public demonstrations of document-borne AI-worm self-propagation through normal workflows in a mainstream commercial productivity suite." และ ผู้เขียนอ้าง prior art ของตัวเอง ว่า "Notably, Morris II demonstrated self-replicating prompt propagation in GenAI-powered email-assistant ecosystems." (Morris II · arXiv:2403.02817 · ปี 2024) ของใหม่จริงคือ "ใน productivity suite เชิงพาณิชย์ที่คนใช้จริงผ่าน workflow ปกติ" ไม่ใช่ "worm ตัวแรก"

กลไก: ทำไมการซ่อนด้วยสีขาวถึงได้ผล

ผู้โจมตีฝังคำสั่งในไฟล์ Word เป็น ตัวอักษรสีขาวบนพื้นขาว ขนาดฟอนต์เล็ก เพื่อให้คนมองไม่เห็น เหตุผลที่มันได้ผลอยู่ที่ pipeline ไม่ใช่ที่โมเดล ผู้เขียนอธิบายตรงตัวว่า:

"rendered as white text on a white background and in a small font size to conceal it from the victim. Since Copilot for Word strips all text formatting like color and font size before passing the text into the underlying Large Language Model (LLM), this text remains fully readable to Copilot even though the victim cannot see it."

การซ่อนที่หลอกตาคนได้ ไม่ได้ซ่อนจากโมเดลเลย เพราะชั้นที่ตัด format ออกอยู่ก่อนโมเดล · ใน PoC ผลลัพธ์คือ "all financial numbers are halved" โดยผู้ใช้ไม่เห็นสัญญาณอะไรเลย

ส่วนที่ทำให้มันเป็น worm

Copilot คัดลอกคำสั่งที่ซ่อนอยู่ ลงไปในเอกสารที่มันสร้างใหม่ ด้วยวิธีซ่อนแบบเดียวกัน ผู้เขียนระบุตำแหน่งและรูปแบบชัดเจน: คัดลอก "the entire malicious prompt into the bottom of the affected document using white text and font size 8"

Willison สรุปประโยคแกนไว้ว่า:

"Copilot may then also copy the hidden instructions into the resulting document, turning that document into a new carrier." (Simon Willison)

เส้นทางแพร่ต่อไม่ต้องมีผู้โจมตีอยู่ในภาพอีกเลย ผู้เขียนเขียนว่า "the victim needs only share this document with coworkers for the attack to spread" เอกสารรอบสองเป็นเอกสาร "internally created" ที่คนในองค์กรไว้ใจโดยธรรมชาติ · พอมีคนเอาไปแนบให้ Copilot ทำงานใหม่ คำสั่งก็ทำงานอีกครั้ง โดยที่ไฟล์ต้นทางของผู้โจมตีไม่ต้องอยู่ในระบบแล้ว

คำที่ผู้เขียนใช้เรียกภาพรวม: "the attack propagates through Word documents, effectively creating a document-borne AI worm."

Willison วางน้ำหนักไว้แบบ first-person hedge ไม่ใช่การเคลมความเป็นที่หนึ่ง: "this is the first one I've seen that deliberately copies instructions to self-replicate itself" · ห้ามอ้าง Willison เป็นแหล่งของคำว่า "ตัวแรกของโลก"

ไทม์ไลน์ responsible disclosure: 144 วัน

วันที่ เหตุการณ์
2026-03-06 รายงานเข้า Microsoft Security Response Center (MSRC)
2026-03-09 MSRC ตอบรับ
2026-03-31 Microsoft ยืนยันพฤติกรรม
2026-04-03 mitigation ชุดแรก deploy
2026-04-09 / 2026-04-10 เคสที่สองในชุดเดียวกัน
2026-06-08 เลื่อนการเปิดเผยตามคำขอของ Microsoft ("At Microsoft's request, public disclosure was moved to 2026-07-15")
2026-07-14 mitigation ชุดที่สอง (อัปเกรดโมเดลเป็น GPT-5.5)
2026-07-15 ยืนยันว่ายัง exploit ได้บน GPT-5.6
2026-07-28 เปิดเผยสาธารณะ

รวม 144 วัน (นับ 6 มี.ค. ถึง 28 ก.ค.) · เดิมกำหนดไว้ 90 วันแล้วขยายสองครั้ง

จุดที่ต้องเล่าสองมุม: Microsoft พูดสวนกับผู้วิจัย

  • ผู้วิจัย: "At the time of publication, no robust mitigation for the broader vulnerability class is available."
  • Microsoft (แถลงต่อ The Register): "We have addressed the findings reported by the researcher" (The Register)

สองคำพูดนี้เข้ากันได้ ไม่ได้ขัดกันจริง: Microsoft ปิด payload ที่ถูกส่งมารายงาน · ผู้วิจัยพูดถึงช่องโหว่ระดับ "ชนิด" ที่ยังเปิดอยู่ ห้ามเล่าข้างเดียวว่า "Microsoft ไม่ทำอะไร" และ ห้ามเล่าว่า "Microsoft แก้แล้วจบ"

ข้อเสนอฝั่งลูกค้าที่ผู้เขียนให้ นำหน้าด้วยประโยคว่า "No customer-side remediation fully addresses the issue" และมีสามข้อ:

  1. ปฏิบัติกับเอกสารจากภายนอกว่าเป็น untrusted เมื่อใช้กับ Copilot
  2. ตรวจเอกสารที่จะแนบก่อนใช้
  3. ตรวจผลลัพธ์ที่ Copilot สร้างก่อนส่งต่อ

สิ่งที่ยังไม่มีหลักฐาน (ต้องอ่านก่อนขึ้นเวที)

  • ไม่มี CVE สำหรับเรื่องนี้ (ตรวจแล้วทั้งใน source, The Register และการค้นหา)
  • ไม่มีหลักฐานว่าถูกใช้โจมตีจริงในธรรมชาติ (in the wild) · เป็น PoC เท่านั้น
  • ยืนยันเฉพาะ Word ผู้เขียนระบุว่า "The exploit is relevant both for the 'magic pen' and the 'Edit with Copilot' functionalities in Word" · ไม่มีการเคลมถึง Excel, PowerPoint หรือ Outlook
  • ไม่ระบุว่ากระทบ consumer Copilot หรือ Microsoft 365 Copilot ตัวไหน ผู้เขียนแตะแค่โหมด Work/Work IQ · ห้ามฟันธงข้างใดข้างหนึ่ง
  • ผู้เขียน กัก payload ไว้ไม่เผยแพร่
  • ข้อสรุปเชิงสถาปัตยกรรมของผู้เขียนเป็น การวิเคราะห์ ไม่ใช่การพิสูจน์ว่ามีการยึดองค์กรได้จริง คำจริงของเขาคือ "the attacker-controlled tokens are already influencing the computation that produces it. The content being inspected participates in the act of inspection."
  • เรื่องการขยายผลเมื่อ Copilot ผูกกับ Microsoft Cowork ผู้เขียน hedge ด้วยคำว่า may: "In such systems the practical impact of the issues described here may scale rapidly." · เป็นการคาดการณ์ของผู้เขียน ไม่ใช่สิ่งที่วัดได้
  • กระทู้ Hacker News ได้ ราว 330 points ณ 30 ก.ค. 2026 (เป็นตัวนับสด ไม่ใช่ตัวเลขคงที่)

คำถามที่ยังไม่มีคำตอบ

  • Microsoft จะออก mitigation ระดับ ชนิดของช่องโหว่ ได้หรือไม่ หรือจะเป็นการปิด payload รายตัวไปเรื่อยๆ
  • ช่องเดียวกันใช้ได้กับ Copilot ใน Excel / PowerPoint / Outlook หรือไม่ · ยังไม่มีใครทดสอบเผยแพร่
  • ผลจริงเมื่อ Copilot ผูกกับ Microsoft Cowork เต็มรูปแบบ (ผู้เขียนคาดว่าจะขยายเร็ว แต่ยังไม่มีการวัด)
  • จะมี CVE ออกภายหลังหรือไม่
■ ไม่อยากพลาดของใหม่

อ่านจบแล้วอยากตามเรื่อง AI แบบนี้ต่อทุกวัน เรามีสรุปข่าวภาษาไทยส่งทาง LINE ทุกเช้า กดเพิ่มเพื่อนไว้ได้เลย ไม่มีค่าใช้จ่าย

เพิ่มเพื่อนใน LINE →
QR เพิ่มเพื่อน LINE ของ TRAINIAC AIคอมพิวเตอร์สแกนด้วยมือถือได้เลย