Microsoft Exchange Flaw Lets Attackers Spoof Any Email Address
This article details a vulnerability in Microsoft Exchange, dubbed "Ghost-Sender," that allows attackers to spoof any email address by exploiting misconfigurations in Exchange Online and on-premises hybrid environments using third-party mail servers. The flaw bypasses standard SPF, DKIM, and DMARC policies, enabling attackers to conduct phishing attacks and fraud. The issue is widespread, with fewer than half of vulnerable organizations having implemented mitigations, and Microsoft's initial response was criticized for delaying action.
The vulnerability, identified by InfoGuard, stems from how Microsoft Exchange Online and on-premises systems handle incoming emails when an external MX record is used. Attackers can leverage this by sending a simple PowerShell command to send an email from any user, regardless of the sender's domain or configured security policies. This allows for the creation of convincing phishing emails, impersonating legitimate accounts like Microsoft's noreply or even an organization's CEO's email address. InfoGuard highlighted that the issue is exacerbated by the fact that Microsoft's own configuration analyzer fails to identify the vulnerability, and enhanced filtering doesn't prevent the attack. The company developed a testing tool to scan domains and send emails to authorized users to demonstrate the ease with which the vulnerability can be exploited. Microsoft initially dismissed the issue as a non-MSRC case and then characterized it as an architectural limitation, offering limited solutions. Organizations can mitigate the risk by implementing partner organization connectors or creating mail flow rules to quarantine suspicious emails.
