Junglewise Threat Intelligence

CVE-2025-64667: Microsoft Exchange Server UI misrepresentation spoofing vulnerability

CVE-2025-64667 · Severity: medium · CVSS 5.3 · Published 2025-12-09

Technologies: Microsoft Exchange Server, Microsoft Exchange Server 2016, Microsoft Exchange Server 2019. Vendors: Microsoft.

Executive brief

Microsoft Exchange Server, the platform used by many organizations for corporate email and calendaring, contains a vulnerability that allows attackers to misrepresent information in the user interface. An unauthorized attacker could use this to spoof communications or system alerts, potentially tricking employees into performing unsafe actions or trusting fraudulent messages. This could lead to successful phishing attempts or the unauthorized disclosure of sensitive business information.

Technical details

A spoofing vulnerability exists in Microsoft Exchange Server due to the misrepresentation of critical information within the User Interface (CWE-451). An unauthenticated attacker can exploit this vulnerability over the network to present fraudulent information to users, potentially facilitating phishing or social engineering attacks. The vulnerability is triggered when the application fails to correctly validate or display security-relevant information to the end user. Microsoft has released security updates to address this issue across affected versions of Exchange Server 2016 and 2019. Exploitation does not require special privileges or user interaction according to the CVSS vector, though the practical impact is centered on spoofing.

Affected products

  • Microsoft Exchange Server 2016 Cumulative Update 1 through 17
  • Microsoft Exchange Server 2019 Cumulative Update 1 through 6

Timeline

  • 2025-12-09: advisory: Initial publication by Microsoft and NVD

References

Related threats