Junglewise Threat Intelligence

CVE-2025-53782: Microsoft Exchange Server privilege escalation in authentication algorithm

CVE-2025-53782 · Severity: high · CVSS 8.4 · Published 2025-10-14

Technologies: Microsoft Exchange Server, Microsoft Exchange Server 2016, Microsoft Exchange Server 2019. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in Microsoft Exchange Server, the platform used by many organizations for business email and calendaring. An attacker with local access to the server could exploit a flaw in how the system verifies identities to gain higher-level administrative permissions. This could allow an unauthorized user to access sensitive communications or interfere with the organization's email operations.

Technical details

A privilege escalation vulnerability exists in Microsoft Exchange Server due to an incorrect implementation of an authentication algorithm (CWE-303). The flaw allows an attacker with local access to the server to bypass or subvert authentication mechanisms to gain elevated privileges. While the attack vector is local, Microsoft's assessment indicates that no prior administrative privileges or user interaction are required for successful exploitation. The vulnerability affects multiple versions of Exchange Server 2016 and 2019. Security updates are available via the Microsoft Security Response Center to remediate this issue.

Affected products

  • Microsoft Exchange Server 2016 Cumulative Update 1 through 17
  • Microsoft Exchange Server 2019 Cumulative Update 1 through 6

Timeline

  • 2025-10-14: disclosed: Initial publication of CVE-2025-53782

References

Related threats