A significant vulnerability in Microsoft Bookings allowed attackers to manipulate meeting details by exploiting insufficient input validation.
The flaw, which Microsoft has largely remedied, enabled malicious actors to inject arbitrary HTML into meeting invitations, alter calendar entries, and potentially facilitate sophisticated phishing attacks.
The vulnerability stemmed from inadequate sanitization of user-supplied input in the Microsoft Bookings API.
Critical fields include appointment.serviceNotes, appointment.additionalNotes, and appointment.body.content lacked proper validation, creating an opportunity for HTML injection attacks.
This security flaw affected organizations using Microsoft Bookings for appointment scheduling within their Microsoft 365 environment.
According to ERNW reports, the vulnerability was particularly exploitable through the “Reschedule” functionality. When a user received a booking confirmation with a rescheduling link, the original unsanitized HTML content was preserved and re-sent within a PUT request.
Attackers could craft malicious inputs like:The vulnerability was particularly exploitable through the “Reschedule” functionality.
When a user received a booking confirmation with a rescheduling link, the original unsanitized HTML content was preserved and re-sent within a PUT request. Attackers could craft malicious inputs like:
More concerning was the ability to manipulate the joinWebUrl parameter to inject deceptive meeting links and images:
Additionally, attackers could inject custom calendar headers in ICS attachments using X-ALT-DESC and additional ORGANIZER entries:
The vulnerability created several significant security risks:
The vulnerability was initially reported to the Microsoft Security Response Center in December 2024, and most aspects were remediated by February 2025.
However, certain parameters like additionalRecipients, startTime, and endTime reportedly remained insufficiently validated.
Security experts recommend that organizations implement strong input validation for all web applications, as outlined in CWE-20 (Improper Input Validation).
For Microsoft Bookings specifically, administrators should consider implementing the security best practices published by Microsoft in March 2025, including controlling access to booking pages and enforcing naming policies.
Organizations using Microsoft Bookings should ensure their systems are updated with the latest security patches and consider implementing additional monitoring for unusual booking activity.
Vulnerability Attack Simulation on How Hackers Rapidly Probe Websites for Entry Points – Free Webinar
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…