Cyber Security News

Microsoft Bookings Vulnerability Let Attackers Alter the Meeting Details

A significant vulnerability in Microsoft Bookings allowed attackers to manipulate meeting details by exploiting insufficient input validation. 

The flaw, which Microsoft has largely remedied, enabled malicious actors to inject arbitrary HTML into meeting invitations, alter calendar entries, and potentially facilitate sophisticated phishing attacks.

The vulnerability stemmed from inadequate sanitization of user-supplied input in the Microsoft Bookings API. 

Critical fields include appointment.serviceNotes, appointment.additionalNotes, and appointment.body.content lacked proper validation, creating an opportunity for HTML injection attacks. 

This security flaw affected organizations using Microsoft Bookings for appointment scheduling within their Microsoft 365 environment.

Reschedule Functionality Exploited for HTML & Link Injection

According to ERNW reports, the vulnerability was particularly exploitable through the “Reschedule” functionality. When a user received a booking confirmation with a rescheduling link, the original unsanitized HTML content was preserved and re-sent within a PUT request.

Attackers could craft malicious inputs like:The vulnerability was particularly exploitable through the “Reschedule” functionality. 

When a user received a booking confirmation with a rescheduling link, the original unsanitized HTML content was preserved and re-sent within a PUT request. Attackers could craft malicious inputs like:

More concerning was the ability to manipulate the joinWebUrl parameter to inject deceptive meeting links and images:

Teams Invite Email

Additionally, attackers could inject custom calendar headers in ICS attachments using X-ALT-DESC and additional ORGANIZER entries:

Custom calendar headers

The vulnerability created several significant security risks:

  • Email and Calendar Manipulation: Attackers could modify event details like descriptions and meeting URLs to mislead recipients.
  • Phishing Vector: The ability to inject HTML allowed for the creation of convincing phishing links within legitimate Microsoft domains.
  • Data Integrity Issues: Meeting times, participant details, and other booking information could be altered.
  • Resource Exhaustion: By manipulating duration parameters, attackers could extend appointments beyond intended time slots, blocking legitimate bookings.
  • Hidden Mailbox Creation: Related vulnerabilities in Microsoft Bookings allowed the creation of hidden mailboxes that bypass standard administrative controls.
Updated Confirmation Email

Mitigation

The vulnerability was initially reported to the Microsoft Security Response Center in December 2024, and most aspects were remediated by February 2025. 

However, certain parameters like additionalRecipients, startTime, and endTime reportedly remained insufficiently validated.

Security experts recommend that organizations implement strong input validation for all web applications, as outlined in CWE-20 (Improper Input Validation). 

For Microsoft Bookings specifically, administrators should consider implementing the security best practices published by Microsoft in March 2025, including controlling access to booking pages and enforcing naming policies.

Organizations using Microsoft Bookings should ensure their systems are updated with the latest security patches and consider implementing additional monitoring for unusual booking activity.

Vulnerability Attack Simulation on How Hackers Rapidly Probe Websites for Entry Points – Free Webinar

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago