Microsoft OWA Flaw Exploited to Maintain Mailbox Access Even After Password Reset

Microsoft OWA Flaw Exploited to Maintain Mailbox Access Even After Password Reset

A newly discovered vulnerability in Microsoft Outlook Web App allows attackers to keep persistent access to compromised mailboxes, bypassing credential rotation. Here's what site owners and IT teams need to know.

A serious security weakness in Microsoft's Outlook Web App (OWA) has been identified, enabling threat actors to retain access to compromised email accounts even after organizations rotate credentials. The flaw, which resides in how OWA manages authentication sessions, allows attackers to continue accessing mailboxes without needing the newly set passwords, posing a significant risk to businesses that rely on Exchange Online or on-premises Exchange servers.

According to security researchers, the vulnerability stems from the way OWA handles session tokens. After a user logs in, OWA issues an authentication cookie that remains valid until it expires or is explicitly revoked. However, under certain conditions, changing the account password does not immediately invalidate active sessions. Attackers who have stolen a valid session token—through means such as phishing, infostealer malware, or man-in-the-middle attacks—can reuse that token to maintain access to the mailbox, bypassing multi-factor authentication if it was satisfied during the initial login. This allows for prolonged espionage and data exfiltration without raising immediate alarms.

Observed in the wild, a Russian-linked cyber-espionage group has actively exploited this behavior to retain footholds in targeted organizations’ email systems. By combining the OWA flaw with other initial access techniques, the group has managed to persist inside compromised environments for extended periods. The impact extends beyond email content; adversaries can leverage mailbox access to reset passwords for other cloud services, orchestrate internal phishing campaigns, or exfiltrate sensitive business communications—all while appearing as legitimate users.

Microsoft has acknowledged the issue and released guidance along with updates to enforce session revocation upon password changes. Administrators should immediately apply the latest cumulative updates for Exchange Server or verify that cloud tenants have the relevant security configurations enabled. Additionally, forcibly revoking all active sessions after a credential reset and enabling continuous access evaluation (CAE) can reduce the window of opportunity. Organizations should also monitor for anomalous sign-in patterns, such as geographically improbable access, and deploy Conditional Access policies to restrict token reuse. For businesses seeking expert assistance in hardening their email infrastructure against such persistence methods, AEU-I provides security-first IT consulting to evaluate and remediate these hidden access paths before they are exploited.

Related AEU services

  • AEU-I IT and security consulting