<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Installapp on Aretiq AI</title><link>https://aretiq.ai/tags/installapp/</link><description>Recent content in Installapp on Aretiq AI</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 22 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://aretiq.ai/tags/installapp/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-45502 — Microsoft Exchange Server EWS InstallApp Server-Side Request Forgery</title><link>https://aretiq.ai/research/vul260622-cve-2026-45502-microsoft-exchange-server-ews-installapp-server-side-request-forgery/</link><pubDate>Mon, 22 Jun 2026 00:00:00 +0000</pubDate><guid>https://aretiq.ai/research/vul260622-cve-2026-45502-microsoft-exchange-server-ews-installapp-server-side-request-forgery/</guid><description>&lt;h2 id="1-overview">1. Overview&lt;/h2>
&lt;p>A server-side request forgery (SSRF) vulnerability exists in Microsoft Exchange Server&amp;rsquo;s Exchange Web Services (EWS) InstallApp operation. When an authenticated user submits a ManifestUrl parameter via the InstallApp SOAP request, Exchange downloads the manifest from the supplied URL. The intranet address check that prevents SSRF is gated on the &lt;code>isBposUser&lt;/code> flag, which is &lt;code>false&lt;/code> for all on-premises Exchange deployments. This means the check is bypassed entirely in non-cloud environments, allowing an authenticated user to force the Exchange server to make HTTP requests to arbitrary internal or external URLs. Microsoft addressed this vulnerability in the June 2026 security update (KB5094139).&lt;/p></description></item></channel></rss>