Executive brief
A vulnerability in Microsoft Exchange Server, the platform used by many organizations for email and calendaring, could allow an unauthorized person to send deceptive communications. An attacker could use this to impersonate legitimate users or services, potentially leading to successful phishing attempts or the distribution of malicious instructions. This issue affects the integrity of communications but does not directly grant access to private data or crash the server.
Technical details
Microsoft Exchange Server is vulnerable to a spoofing attack due to improper input validation. An unauthenticated attacker can exploit this vulnerability over the network without any user interaction. The root cause is a failure to correctly validate specific inputs, which allows an attacker to manipulate communication metadata to appear as a different entity. While the vulnerability does not directly lead to data disclosure or a denial of service, it significantly impacts the integrity of the communication flow. Microsoft has released security updates to address this issue across affected versions of Exchange Server 2016 and 2019.
Affected products
- Microsoft Exchange Server 2016 Cumulative Update 1 through 17
- Microsoft Exchange Server 2019 Cumulative Update 1 through 6
Timeline
- 2025-10-14: disclosed: Vulnerability published by Microsoft and NVD