HomeSecurityVulnerability in Microsoft Events platform exposes personal data

Vulnerability in Microsoft Events platform exposes personal data

A major security vulnerability has been discovered in the Microsoft Events, which could allow attackers to gain access to personal user information from two separate databases: the event registration list and the waitlist.

See also: Inboxfuscation: New tool bypasses Microsoft Exchange Inbox Rules

Microsoft Events
Vulnerability in Microsoft Events platform exposes personal data

The vulnerability, discovered by a 15-year-old vulnerability hunter known as Faav, exposed sensitive user data, including full names, email addresses, phone numbers, and, in some cases, physical addresses. The vulnerability was responsibly disclosed to Microsoft and has already been patched.

The investigation began when the researcher began examining the events.microsoft.com, which led to the discovery of several API endpoints in the msevents.microsoft.com domain.

Initial vulnerability testing on various endpoints did not return any sensitive data. The first major discovery came when an OData injection in the /api/GetEvents endpoint. However, this initial entry point proved to be a dead end, as it only returned non-sensitive, public event information and threw errors when attempting to access other data tables such as accounts or contacts.

A similar injection vulnerability was found in another endpoint /api/GetEventCustomRegistrationFields, which allowed enumeration of all Microsoft events but did not leak user data.

See also: Microsoft: Fixed a Defender bug that affected Firefox for five years

Vulnerability in Microsoft Events platform exposes personal data
Vulnerability in Microsoft Events platform exposes personal data

The critical discovery was made in a POST endpoint named /api/CheckEventRegistration. This function was designed to check whether a user's email was already registered for a particular event. The researcher found that by injecting malicious payloads into the email and eventId fields, it was possible to trick the system.

A specific OData injection technique revealed that the endpoint made two separate requests to two different databases. By carefully shaping the input, Faav was able to target each database separately. One injection allowed the enumeration of the entire Waitlist, which contained fields such as full name, phone, address, company, and email addresses, including many from government and corporate domains.

By reversing the injection technique, the researcher was able to access the second database, the Event Registration list. This database contained personal details such as first name, last name, phone number, company name, and country. Some events even included custom fields for Partner IDs and Tenant IDs.

See also: Microsoft Outlook: It's now free for Mac with no subscription required

Vulnerability in Microsoft Events platform exposes personal data
Vulnerability in Microsoft Events platform exposes personal data

The researcher noted that there were no speed limits, meaning an attacker could schedule the extraction of all data from both databases. After successfully demonstrating the potential for this information to be leaked, Faav stopped further testing and reported the findings to the Microsoft Security Response Center (MSRC) on July 23, 2025. According to the timeline provided, Microsoft acknowledged the issue and completed the fix on August 26, 2025.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS