Junglewise Threat Intelligence

CVE-2025-33051: Microsoft Exchange Server information disclosure

CVE-2025-33051 · Severity: high · CVSS 7.5 · Published 2025-08-12

Technologies: Microsoft Exchange Server, Microsoft Exchange Server 2016, Microsoft Exchange Server 2019. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in Microsoft Exchange Server, the platform used by many organizations for business email and calendaring. This flaw allows an unauthorized person to access sensitive information over the network without needing a username or password. If exploited, this could lead to the exposure of private corporate data or internal system details, potentially aiding further attacks against the organization.

Technical details

Microsoft Exchange Server is vulnerable to an information disclosure flaw (CWE-200) when handling certain network requests. The vulnerability allows an unauthenticated, remote attacker to disclose sensitive information by sending a specially crafted request over the network. According to the CVSS vector, the attack requires no special privileges or user interaction and has a high impact on confidentiality. Affected versions include various cumulative updates for Exchange Server 2016 and 2019. Microsoft has released security updates to address this issue; administrators should refer to the Microsoft Security Update Guide for patching instructions.

Affected products

  • Microsoft Exchange Server 2016 Cumulative Update 1 through 17
  • Microsoft Exchange Server 2019 Cumulative Update 1 through 6

Timeline

  • 2025-08-12: disclosed: Initial publication of the vulnerability details.
  • 2025-08-12: advisory: Microsoft released a security advisory and update guide.

References

Related threats