Errors during the implementation of the Autodiscover feature of Microsoft Exchange have leaked about 100,000 login names and passwords for Windows domains worldwide.
In a new report by Amit Serper, AVP of Security Security at Guardicore, the researcher reveals how the implementation of the Autodiscover protocol causes Windows credentials to be sent to untrusted third‑party sites.

See also: BadAlloc bugs expose millions of IoT devices to hijack
What is Microsoft Exchange Autodiscover
Microsoft Exchange uses an Autodiscover feature to automatically configure a user's mail client, such as Microsoft Outlook, with the organization's default mail settings.
When an Exchange user enters their email address and password into a mail client, such as Microsoft Outlook, the mail client then attempts to authenticate against various Exchange Autodiscover URLs.
See also: Patch Tuesday September 2021: Microsoft fixes critical bugs
During this authentication process, the login name and password are automatically sent to the Autodiscover URL.
The Autodiscover URLs to which they will connect are derived from the email address configured in the client.
For example, when Serper tested the Autodiscover feature using the email ‘amit@example.com’, it found that the mail client attempted to authenticate against the following Autodiscover URL addresses:
- https://Autodiscover.example.com/Autodiscover/Autodiscover.xml
- https://Autodiscover.example.com/Autodiscover/Autodiscover.xml
- https://example.com/Autodiscover/Autodiscover.xml
- https://example.com/Autodiscover/Autodiscover.xml
The mail client would try each URL until it successfully authenticates with the Microsoft Exchange server and the configuration information is sent back to the client.
Leak of credentials to external domains
If the client could not authenticate to the above URLs, Serper found that some mail clients, including Microsoft Outlook, would execute a “back-off” process. This process attempts to create additional URLs for authentication, such as on the autodiscover.[tld] domain, where the TLD comes from the user's email address.
In this case, the URL generated is https://Autodiscover.com/Autodiscover/Autodiscover.xml.
In a new report by Amit Serper, the AVP of Guardicore for Research Security, the researcher reveals how the implementation of the Autodiscover protocol causes the identification of mail clients on untrusted domains, such as autodiscover.com.
Since the email user's organization does not own this domain and the credentials are automatically sent to the URL, it will allow the domain owner to collect any credentials that are sent to it.
See also: Netgear: Fixes serious bugs in over a dozen smart switches
Mitigation of Microsoft Exchange Autodiscover leaks
Serper provided some suggestions that organizations and developers can use to mitigate these Microsoft Exchange Autodiscover leaks.
For organizations that use Microsoft Exchange, they should block all Autodiscover.[tld] domains on the firewall or DNS server, so your devices cannot connect to them. It is also recommended that organizations disable basic authentication, as it essentially sends credentials in cleartext.
Information source: bleepingcomputer.com
