Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability has been identified in Pexip Infinity's Secure Scheduler for Exchange service, affecting versions 15.0 through 38.0. This flaw could allow unauthorized remote access to sensitive data and disrupt service availability by consuming excessive resources. The primary concern is to confirm if our environment is running the affected software.
- Unauthorized access to sensitive data and service disruption.
- Potential for data exposure and resource exhaustion.
- Confirm relevance and assess potential exposure.
Attack Path
How an attacker could exploit the issue
An attacker can exploit this vulnerability by targeting the Secure Scheduler for Exchange service, which integrates with external calendar systems. Since no authentication is required and the vulnerability is network-accessible, an attacker can remotely trigger this issue to read sensitive data or cause a denial of service by excessively consuming resources.
- No authentication required to initiate attack.
- Vulnerability triggered via external calendar integration.
- Risk of sensitive data exposure and denial of service.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability in Pexip Infinity's Secure Scheduler for Exchange service, when configured with Office 365 Legacy Exchange Tokens, could allow a remote attacker to access sensitive data and cause a denial of service.
- Sensitive data disclosure and resource exhaustion.
- Unauthenticated remote access to service.
- Disruption of service availability.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability in Pexip Infinity's Secure Scheduler for Exchange service could impact organizations using Office 365 legacy Exchange tokens. The primary teams responsible for addressing this would likely be the platform or infrastructure team managing Pexip Infinity, in coordination with the security team and potentially the vendor management team if Pexip is a managed service. The first practical step is to identify all Pexip Infinity instances, confirm their exposure and criticality, and then determine the accountable owner for remediation planning.
- Platform/Infrastructure teams own the fix.
- Verify system reachability and business criticality.
- Plan remediation based on identified risk.