Vulnerability allows an attacker to Hijack accounts in a very simple way, by just exporting & importing cookies of an user account from one system to attacker’s system, and our results shows that even after logout by victim, the attacker is still able to reuse cookies at his end. In May 2012, another Indian security researcher Rishi Narang claimed similar Vulnerability. Many websites including Microsoft services uses cookies to store the session information in the user’s web browser. There are various ways, attacker can steal cookies depending upon various factors: Having access to victim’s system (Success Rate – 100%):
Source: https://thehackernews.com/2012/12/hotmail-and-outlook-cookie-handling.html

