$ techbeacon▋
CVE & Exploits

Researchers Reveal Microsoft 365 Direct‑Send Bypass That Lets Attackers Spoof Internal Emails Without Credentials

Researchers Reveal Microsoft 365 Direct‑Send Bypass That Lets Attackers Spoof Internal Emails Without Credentials

A security researcher collective known as GBHackers has disclosed a method for sending unauthenticated messages that appear to originate from internal Microsoft 365 users, exploiting a configuration oversight in Exchange Online.

The technique hinges on leaving a single Simple Mail Transfer Protocol (SMTP) field empty when crafting a message. By doing so, the attacker can bypass the RejectDirectSend setting, which is intended to block direct‑send attempts from external sources. The result is a message that passes Microsoft 365’s inbound filters and is delivered to recipients as though it were sent by a legitimate employee.

RejectDirectSend is a control that many organizations enable to mitigate spam and spoofing. However, the bypass does not stem from a code flaw in Microsoft’s services; rather, it exploits the way the control processes incomplete SMTP headers. When the required field is omitted, the service treats the message as internal, allowing it to be relayed without any credential check.

Security experts warn that the ability to impersonate internal users without needing stolen passwords could facilitate phishing campaigns, business‑email compromise, and the distribution of malware. Because the messages appear to come from trusted addresses, they are more likely to be opened by unsuspecting recipients, potentially compromising sensitive data or leading to credential theft.

Microsoft has acknowledged the report and emphasized that the issue is tied to configuration choices rather than a software vulnerability. The company recommends that administrators review their RejectDirectSend policies, enforce stricter header validation, and consider additional anti‑spoofing measures such as DMARC, DKIM, and SPF. Organizations are also urged to monitor mail flow logs for anomalous patterns that could indicate exploitation of the bypass.

The discovery underscores the importance of comprehensive email security hygiene in cloud environments. As attackers continue to probe the nuances of widely deployed services, experts say that regular audits of security settings and prompt application of guidance from vendors remain essential to maintaining the integrity of corporate communications.

Source: GBHackers
Deepak Chandra Meena — Deepak covers the dark web and underground hacking forums, reporting on marketplace activity and access broker listings. Monitors Tor-based forums and encrypted leak channels.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related