Executive brief
Microsoft Exchange Server, the platform used by organizations for email and calendaring, contains a security flaw in its authentication process. An attacker who already has basic user access to the network could exploit this weakness to gain higher-level administrative privileges. This could allow them to access sensitive emails, disrupt communications, or gain further control over the corporate network.
Technical details
A privilege escalation vulnerability exists in Microsoft Exchange Server due to weak authentication mechanisms (CWE-1390). An attacker with low-privileged user credentials can exploit this flaw over the network without any user interaction. Successful exploitation allows the attacker to elevate their permissions, potentially gaining administrative control over the Exchange environment. The vulnerability affects multiple versions of Exchange Server 2016 and 2019. Microsoft has released security updates to address this issue, and administrators are advised to apply the latest Cumulative Updates.
Affected products
- Microsoft Exchange Server 2016 Cumulative Update 1 through 17
- Microsoft Exchange Server 2019 Cumulative Update 1 through 6
Timeline
- 2025-10-14: disclosed
- 2025-10-14: advisory