Moslem Haghighian
Discoveries and Talk

Information disclosure vulnerabilities in Microsoft Outlook

Walkthrough of an Outlook / Exchange information-disclosure issue reachable by sending a crafted PDF that abuses a file-download token via an OAST-style callback.

Watch on YouTube →

Information disclosure in Microsoft Outlook

Demonstration of a vulnerability affecting Outlook and Exchange services.

By delivering a crafted PDF, an attacker can trigger access through a file download token and exfiltrate or observe sensitive signals using an OAST (Out-of-Band Application Security Testing) callback pattern.

Watch: YouTube