Junglewise Threat Intelligence

CVE-2025-25006: Microsoft Exchange Server spoofing vulnerability

CVE-2025-25006 · Severity: medium · CVSS 5.3 · Published 2025-08-12

Technologies: Microsoft Exchange Server, Microsoft Exchange Server 2016, Microsoft Exchange Server 2019. Vendors: Microsoft.

Executive brief

Microsoft Exchange Server, the platform used by many organizations for corporate email and calendaring, contains a vulnerability that allows an unauthorized person to send deceptive communications. An attacker could use this to impersonate legitimate users or services, potentially tricking employees into revealing sensitive information or performing unauthorized actions. This type of spoofing can damage a company's reputation and lead to further security breaches if staff act on fraudulent messages.

Technical details

A spoofing vulnerability exists in Microsoft Exchange Server due to improper handling of special elements (CWE-167). An unauthenticated attacker can exploit this over the network without any user interaction. By sending specially crafted requests, the attacker can manipulate message headers or other metadata to misrepresent the origin of communications. This vulnerability affects multiple versions of Exchange Server 2016 and 2019. Microsoft has released security updates to address this issue; administrators should refer to the Microsoft Security Update Guide for specific patch details.

Affected products

  • Microsoft Exchange Server 2016 Cumulative Update 1 through 23
  • Microsoft Exchange Server 2019 Cumulative Update 1 through 14

Timeline

  • 2025-08-12: advisory: Initial disclosure by Microsoft and NVD

References

Related threats