Executive brief
A vulnerability in Microsoft Exchange Server, the platform used by many organizations for email and calendaring, could allow an authorized user to gain higher-level administrative permissions. An attacker with basic access to the email system could exploit this flaw to access sensitive data or disrupt communications. This issue requires the attacker to have existing credentials on the network and navigate specific environmental complexities to succeed.
Technical details
Microsoft Exchange Server is vulnerable to privilege escalation due to improper input validation. An attacker with low-privileged authenticated access can exploit this vulnerability over the network to gain elevated permissions. The attack complexity is rated as high, suggesting that specific environmental conditions or configurations must be met for successful exploitation. The vulnerability affects multiple versions of Exchange Server 2016 and 2019. Microsoft has released security updates to address this issue, and users are advised to apply the latest Cumulative Updates (CU).
Affected products
- Microsoft Exchange Server 2016 Cumulative Update 1 through 23
- Microsoft Exchange Server 2019 Cumulative Update 1 through 14
Timeline
- 2025-12-09: disclosed
- 2025-12-09: advisory: Microsoft released the security update guide for this vulnerability.