The Autodiscover Scare of 2021, and the Lesson That Outlasted It

Written in late September and early October 2021, in the two weeks after Microsoft disclosed the Autodiscover vulnerability. The vulnerability itself was patched long ago and is not a current threat. What follows is kept for the lesson at the end, which is not about Autodiscover at all.

Itwerx is a service-disabled veteran-owned managed IT and cybersecurity provider serving businesses in Seattle, Bellevue, Everett, Lynnwood and Snohomish County, founded in 2005.

What was true in the fall of 2021

Microsoft’s Autodiscover protocol, the default method most email clients use to configure a corporate mailbox automatically, had a design flaw that could be tricked into handing over network login credentials. It affected phones, laptops and any device running common mail software, which at the time was effectively everyone using email on a personal device.

The practical advice then was to assume some credentials would be exposed before every affected client could be patched, and to compensate with layered defenses: endpoint monitoring, multi-factor authentication, and enough alerting to catch a compromised login quickly rather than relying on the perimeter to hold.

The follow-up, and the part worth keeping

A week later, testing found that essentially all common mobile mail clients were vulnerable to some variant of the same class of issue, and a large share of small-office routers and access points carried known flaws of their own. Microsoft’s position at the time was that affected clients should not have handed over credentials unencrypted in the first place – true, but beside the point for anyone who had already deployed one of the many clients that did.

That combination raised an uncomfortable question: if an insurer’s position is that a client “willingly handed over” its own login, does the policy still pay out? It is the same logic an insurer uses when a burglary claim is denied because the keys were left in the door.

The lesson that outlasted the vulnerability: before you need to file a cyber insurance claim, ask your carrier in writing where they stand on scenarios like this one. A verbal assurance from an agent is not a coverage position. Get the answer in writing while it costs nothing to ask, not during the week you are trying to recover from a breach.

That is still good advice today, for an entirely different set of vulnerabilities than the one that prompted it.

Itwerx Corp is a service-disabled veteran-owned small business providing IT services across Seattle, Bellevue, Everett and Snohomish County. This is the kind of thing our cybersecurity work deals with – talk to us about yours.