# Microsoft Exchange "Ghost-Sender" Vulnerability Lets Attackers Impersonate Any User
## The Threat
A critical spoofing vulnerability in Microsoft Exchange is allowing attackers to send emails from any user—internal or external—with no authentication required. Discovered and disclosed by Swiss cybersecurity firm InfoGuard, the flaw exploits a widespread misconfiguration in hybrid Exchange environments where organizations route incoming email through third-party mail servers or spam filters.
The vulnerability, dubbed "Ghost-Sender," affects organizations using Exchange Online or Exchange Server in hybrid mode with an external mail exchange (MX) record pointing to a third-party provider. By default, Exchange accepts incoming emails from these external MX records without proper sender verification, allowing attackers to craft spoofed messages that bypass SPF, DKIM, and DMARC authentication mechanisms—the industry-standard email security controls designed explicitly to prevent this type of attack.
The impact is severe. An attacker can fabricate emails appearing to come from a CEO demanding fraudulent wire transfers, a vendor's billing department requesting payment for fake invoices, or even Microsoft's own noreply account. In one demonstration, InfoGuard showed an email claiming to originate from a Microsoft corporate address, complete with the actual sender's Outlook profile picture rendered in the inbox. Most alarmingly, Microsoft support has confirmed that this vulnerability—or a related variant—is already being exploited in active campaigns.
## Severity and Impact
| Attribute | Details |
|-----------|---------|
| Vulnerability Name | Ghost-Sender (Microsoft Exchange Email Spoofing) |
| CVE ID | CVE information pending from official Microsoft advisory |
| CVSS Score | Critical (pending official assessment) |
| Attack Vector | Network-based; requires ability to send email to vulnerable MX record |
| Attack Complexity | Low (trivial to execute; single PowerShell command sufficient) |
| Authentication Required | None |
| User Interaction Required | No |
| Scope | Changed (impacts email recipient trust model) |
| Affected Systems | Exchange Online with external MX record; Exchange Server in hybrid mode |
| CWE | CWE-290 (Authentication Bypass by Spoofing), CWE-347 (Improper Verification of Cryptographic Signature) |
## Affected Products
Microsoft Exchange (Hybrid Configurations):
Vulnerable Configuration Criteria:
Organizations using pure Exchange Online with Microsoft's MX record or pure on-premises Exchange without external MX records are not affected.
## Mitigations
Immediate Actions:
1. Implement Strict Email Authentication: Enforce DMARC with p=reject policy (not p=quarantine). While the vulnerability bypasses these controls in certain configurations, strict DMARC remains critical defense-in-depth.
2. Add Microsoft-Specific Authentication Headers: Configure Exchange to require and validate the X-MS-Exchange-Organization-OriginalArrivalTime and other Microsoft-specific headers that third-party attackers cannot spoof. Reject emails lacking proper Microsoft headers when claiming to originate from your own domain.
3. Enable Tenant Allow/Block List Rules: Use Microsoft Defender for Office 365 to create explicit allow rules for trusted senders and block rules for external addresses claiming to be internal users. Configure alerts when external emails claim internal sender addresses.
4. Implement Conditional Access Policies: Restrict email relay to authenticated systems only. Prevent any external system from sending mail claiming internal user identities.
5. Network Segmentation: Route all inbound email through Microsoft's secure infrastructure when possible. If third-party filtering is required, use dedicated appliances with strict authentication relay policies—never allow relay of internal addresses.
6. Monitor and Alert: Deploy email gateway logging to detect and alert on any email claiming an internal sender address arriving from external sources. Review MX record configuration and mail flow logs regularly.
Configuration Review:
Vendor Patching:
Monitor Microsoft's official advisory for permanent security updates. InfoGuard has noted that Microsoft deployed and subsequently rolled back a mitigation, suggesting official fixes are in development.
## References
---
## HackWire Analysis
Ghost-Sender represents a perfect storm of infrastructure complexity and authentication fragmentation. Email authentication standards (SPF, DKIM, DMARC) have become security theater—they exist on paper in most compliance policies but fail catastrophically when hybrid configurations bypass them entirely. The real story isn't the vulnerability itself; it's that fewer than half of affected organizations have applied mitigations despite email spoofing remaining one of the highest-ROI attack vectors.
Why? Hybrid Exchange configurations are increasingly common as enterprises migrate selectively to the cloud, and third-party spam filters remain popular because they predate cloud adoption. Organizations inherit these configurations without regular architectural review. The misconfiguration persists silently until it's exploited.
The active exploitation confirms what defenders already know: email spoofing is profitable. A single impersonated CEO can authorize six-figure transfers. A spoofed vendor invoice can slip through accounting review. DMARC failing under these conditions isn't a technical edge case—it's the current threat model.
Defenders should treat this as a forcing function to audit MX records and mail routing architecture immediately. If your organization has an external MX record pointing anywhere but Microsoft, assume it's vulnerable and implement the conditional access controls outlined above. Email authentication is broken in hybrid mode; layered defenses (explicit allow lists, header validation, user education) are the only reliable countermeasure. Most critically, stop assuming that internal email can be trusted just because it appears in someone's inbox.
— HackWire Editorial
---
## Related Coverage