A vulnerability in Microsoft's Copilot for Word allows attacker-controlled instructions in an attached document to hijack the AI and alter the output text, potentially propagating the attack to new documents. The attack can be concealed by embedding malicious instructions in a seemingly benign document. Microsoft has deployed multiple fixes, but the broader vulnerability class remains unmitigated. The vulnerability can be exploited through normal user workflows, making it a significant security concern.