Executive brief
Microsoft Exchange Server, the widely used corporate email and calendaring platform, contains a vulnerability that allows attackers to misrepresent information in the user interface. This could allow an unauthorized person to spoof communications or system alerts, potentially tricking employees into trusting malicious content or providing sensitive information. Successful exploitation could lead to unauthorized access to data or a loss of trust in internal communications.
Technical details
A spoofing vulnerability exists in Microsoft Exchange Server due to the improper validation of syntactic correctness of input and insufficient verification of data authenticity (CWE-345, CWE-1286). This leads to a User Interface (UI) Misrepresentation of Critical Information (CWE-451). An unauthenticated attacker can exploit this over the network to present misleading information to users. The vulnerability affects Exchange Server 2016, 2019, and the Subscription Edition. Microsoft has released updates to address this issue, and users are advised to upgrade to the latest cumulative updates or the fixed version of the Subscription Edition (15.02.2562.037 or later).
Affected products
- Microsoft Exchange Server 2016 Cumulative Update 23
- Microsoft Exchange Server 2019 Cumulative Update 14
- Microsoft Exchange Server 2019 Cumulative Update 15
- Microsoft Exchange Server Subscription Edition versions up to (excluding) 15.02.2562.037
Timeline
- 2026-02-10: disclosed: Initial disclosure by Microsoft
- 2026-02-10: advisory: MSRC advisory published