A major security vulnerability has been discovered in the Microsoft Events, which could allow attackers to gain access to personal user information from two separate databases: the event registration list and the waitlist.
See also: Inboxfuscation: New tool bypasses Microsoft Exchange Inbox Rules

The vulnerability, discovered by a 15-year-old vulnerability hunter known as Faav, exposed sensitive user data, including full names, email addresses, phone numbers, and, in some cases, physical addresses. The vulnerability was responsibly disclosed to Microsoft and has already been patched.
The investigation began when the researcher began examining the events.microsoft.com, which led to the discovery of several API endpoints in the msevents.microsoft.com domain.
Initial vulnerability testing on various endpoints did not return any sensitive data. The first major discovery came when an OData injection in the /api/GetEvents endpoint. However, this initial entry point proved to be a dead end, as it only returned non-sensitive, public event information and threw errors when attempting to access other data tables such as accounts or contacts.
A similar injection vulnerability was found in another endpoint /api/GetEventCustomRegistrationFields, which allowed enumeration of all Microsoft events but did not leak user data.
See also: Microsoft: Fixed a Defender bug that affected Firefox for five years

The critical discovery was made in a POST endpoint named /api/CheckEventRegistration. This function was designed to check whether a user's email was already registered for a particular event. The researcher found that by injecting malicious payloads into the email and eventId fields, it was possible to trick the system.
A specific OData injection technique revealed that the endpoint made two separate requests to two different databases. By carefully shaping the input, Faav was able to target each database separately. One injection allowed the enumeration of the entire Waitlist, which contained fields such as full name, phone, address, company, and email addresses, including many from government and corporate domains.
By reversing the injection technique, the researcher was able to access the second database, the Event Registration list. This database contained personal details such as first name, last name, phone number, company name, and country. Some events even included custom fields for Partner IDs and Tenant IDs.
See also: Microsoft Outlook: It's now free for Mac with no subscription required

The researcher noted that there were no speed limits, meaning an attacker could schedule the extraction of all data from both databases. After successfully demonstrating the potential for this information to be leaked, Faav stopped further testing and reported the findings to the Microsoft Security Response Center (MSRC) on July 23, 2025. According to the timeline provided, Microsoft acknowledged the issue and completed the fix on August 26, 2025.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
