Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft 365 PDF Export LFI Vulnerability Allows Access to Sensitive Server Data

Microsoft 365 PDF Export LFI Vulnerability Allows Access to Sensitive Server Data

Posted on July 9, 2025July 9, 2025 By CWS

A important Native File Inclusion (LFI) vulnerability was lately found in Microsoft 365’s Export to PDF performance, probably permitting attackers to entry delicate server-side knowledge, together with configuration information, database credentials, and software supply code. 

The vulnerability, reported by safety researcher Gianluca Baldi and subsequently patched by Microsoft, earned a $3,000 bounty reward for its vital impression on enterprise safety. 

Key Takeaways1. Native File Inclusion (LFI) flaw in Microsoft 365’s Export to PDF characteristic allowed attackers to entry delicate server-side information.2. Malicious HTML tags pull server information into the transformed PDF.3. Uncovered configs, credentials, and attainable cross-tenant knowledge.4. Microsoft patched the vulnerability after safety researcher Gianluca Baldi reported it by way of their bug bounty program.

This flaw exploited an undocumented habits in Microsoft Graph APIs that enabled HTML-to-PDF conversion with embedded file inclusion capabilities.

Overview of Native File Inclusion (LFI) vulnerability

Gianluca Bald found the vulnerability throughout a consumer net software evaluation, the place a file conversion characteristic remodeled paperwork into PDF format by way of Microsoft 365 SharePoint integration. 

The Microsoft Graph APIs formally help PDF conversion from a number of codecs, together with CSV, DOC, DOCX, ODP, ODS, ODT, POT, POTM, POTX, PPS, PPSX, PPSXM, PPT, PPTM, PPTX, RTF, XLS, and XLSX, by way of the format HTTP parameter. Nevertheless, an undocumented habits allowed HTML-to-PDF conversion, creating an sudden assault floor. 

This conversion course of lacked correct enter validation and file path restrictions, enabling path traversal assaults that might entry information outdoors the server’s designated root listing.

The exploitation course of concerned embedding malicious HTML tags comparable to ,

Malicious HTML file

Attackers might craft specifically designed HTML information containing these tags with file paths pointing to delicate system information like net.config, win.ini, or different important configuration information. 

The assault sequence consisted of three easy steps: first, importing a malicious HTML file through the Microsoft Graph API; second, requesting the file conversion to PDF format by way of the API endpoint; and third, downloading the ensuing PDF containing the embedded native file contents. 

Request the file in PDF format

This Native File Inclusion vulnerability successfully bypassed commonplace safety controls and file entry restrictions.

Mitigations

The safety implications of this vulnerability prolonged past easy file disclosure, probably exposing Microsoft secrets and techniques, database connection strings, software supply code, and, in multi-tenant environments, cross-tenant knowledge publicity situations. 

The vulnerability obtained an “Necessary” severity ranking from Microsoft Safety Response Middle (MSRC), reflecting its potential for vital knowledge breaches in enterprise environments. 

Organizations using Microsoft 365’s doc conversion options have been in danger till Microsoft carried out correct enter validation and file path sanitization controls. 

The remediation course of concerned limiting HTML tag processing throughout PDF conversion and implementing strict file path validation to forestall listing traversal assaults. 

Microsoft has since patched this vulnerability, however the incident highlights the significance of thorough safety testing for undocumented API behaviors and file processing options.

Suppose like an Attacker, Mastering Endpoint Safety With Marcus Hutchins – Register Now

Cyber Security News Tags:Access, Data, Export, LFI, Microsoft, PDF, Sensitive, Server, Vulnerability

Post navigation

Previous Post: Chinese Hackers Exploit Microsoft Exchange Servers to Steal COVID-19 Research Data
Next Post: Nippon Steel Subsidiary Blames Data Breach on Zero-Day Attack

Related Posts

Critical Vulnerabilities Uncovered in Zero Trust Network Access Products of Check Point, Zscale,r and NetSkope Critical Vulnerabilities Uncovered in Zero Trust Network Access Products of Check Point, Zscale,r and NetSkope Cyber Security News
North Korean Hackers Trick Users With Weaponized Zoom Apps to Execute System-Takeover Commands North Korean Hackers Trick Users With Weaponized Zoom Apps to Execute System-Takeover Commands Cyber Security News
OceanLotus Hacker Group Targeting Xinchuang IT Ecosystems to Launch Supply Chain Attacks OceanLotus Hacker Group Targeting Xinchuang IT Ecosystems to Launch Supply Chain Attacks Cyber Security News
Cornwell Quality Tools Data Breach Cornwell Quality Tools Data Breach Cyber Security News
Fake Installers Deploy SharkLoader Malware in Networks Fake Installers Deploy SharkLoader Malware in Networks Cyber Security News
Microsoft’s Copilot Disclaimer Sparks Security Debate Microsoft’s Copilot Disclaimer Sparks Security Debate Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles
  • Critical Vulnerability in Oracle PeopleSoft Exploited Globally
  • Kiteworks Recommends Nine-Hour System Shutdown Amid Cyber Threat
  • New Botnet x47.c Leverages AI for Advanced Cyber Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles
  • Critical Vulnerability in Oracle PeopleSoft Exploited Globally
  • Kiteworks Recommends Nine-Hour System Shutdown Amid Cyber Threat
  • New Botnet x47.c Leverages AI for Advanced Cyber Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark