Junglewise Threat Intelligence

CVE-2025-25005: Microsoft Exchange Server improper input validation tampering vulnerability

CVE-2025-25005 · Severity: medium · CVSS 6.5 · Published 2025-08-12

Technologies: Microsoft Exchange Server, Microsoft Exchange Server 2016, Microsoft Exchange Server 2019. Vendors: Microsoft.

Executive brief

Microsoft Exchange Server, a widely used corporate email and calendar platform, contains a vulnerability that could allow an authorized user to tamper with data. An attacker with basic login credentials could modify information they should not have access to, potentially compromising the integrity of communications or organizational records. This issue requires a security update to prevent unauthorized changes to server data.

Technical details

A tampering vulnerability exists in Microsoft Exchange Server due to improper input validation. An authenticated attacker with low-level privileges can exploit this flaw over the network to modify data without authorization. The vulnerability is classified under CWE-20 (Improper Input Validation). While the attack requires authentication, it does not require user interaction or high-level administrative rights. Microsoft has released security updates to address this issue across affected versions of Exchange Server 2016 and 2019.

Affected products

  • Microsoft Exchange Server 2016 Cumulative Update 1 through 17
  • Microsoft Exchange Server 2019 Cumulative Update 1 through 6

Timeline

  • 2025-08-12: disclosed
  • 2025-08-12: advisory

References

Related threats