Microsoft Exchange Server Privilege Escalation Vulnerability

Vulnerability

A vulnerability allowing unauthorized privilege escalation has been identified in Microsoft Exchange Server. This issue arises from an incorrect implementation of the authentication algorithm, which could enable an attacker to elevate privileges locally. Exploitation of this vulnerability would allow an attacker to take control of the mailboxes of all Exchange users, including access to read emails and download attachments.

Impact

Successful exploitation of this vulnerability would allow an attacker to gain elevated privileges, enabling them to take over the mailboxes of all Exchange users and access their emails and attachments.

Remediation

Users can apply the security update for Microsoft Exchange Server 2016 Cumulative Update 23, Exchange Server Subscription Edition RTM, Exchange Server 2019 Cumulative Update 14, or Exchange Server 2019 Cumulative Update 15. Security update download links are available on the Microsoft Update Catalog.

Added: Oct 14, 2025, 5:20 PM
Updated: Oct 14, 2025, 10:02 PM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
5.0
exploitability
3.8
remediation
7.7
relevance
0.8
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.