A Chinese developer known only as ramen-hero pointed out the fact that Microsoft leaks the CID identifier in plain text when DNS queries are performed, a special piece of information that attackers could use to identify traffic originating from a specific person/account.
The problem can be found on Outlook.com, OneDrive, and Microsoft ’s account page , where despite the presence of an HTTPS connection, the CID associated with each account is embedded in the URL. As ramen-hero explains, an attacker or a government agency monitoring DNS traffic can easily identify connections originating from an individual based on their CID. The problem is that this CID is unique to each user account and allows attackers to link various Microsoft services to users who would like to keep their private lives private for various reasons. The CID can reveal a person’s account picture, display the name attached to each account, as well as the date the account was created. Additionally, using some code tricks, the CID can also reveal the person’s location via a Calendar app, which publicly displays CIDs and weather forecasts. If the user receives weather information in the calendar app , then the weather location identifier can be reliably used to detect the user's location on a daily basis.

Expanding on ramen-hero's research, other users have also pointed out that because the CID is part of the domain name in various communications, attackers don't necessarily need to inspect DNS traffic.
The CID has, moreover, been leaked during TLS handshakes even in Tor traffic, if the exit node is monitored.
"If you have linked your Microsoft account to your Skype account," says ramen-hero, "anyone who knows the primary alias of your Microsoft account can also obtain your CID using the People app."
This opens the door to serious privacy concerns from attackers, and those pesky government agencies can now correlate Internet traffic to individual individuals and track them.
What Microsoft in this situation is not to add the CID in plain text inside URLs and to protect Web and API queries from revealing personal and identifiable information from the user's CID.
