Microsoft Exchange Server
cpe:2.3:a:microsoft:exchange_srv:*:*:*:*:*:*:*
- <= 15.01.2507.063
A user interface misrepresentation vulnerability has been identified in Microsoft Exchange Server. This issue allows an unauthorized attacker to perform spoofing over the network by manipulating critical information displayed to users. The vulnerability affects Microsoft Exchange Server 2016 Cumulative Update 23, Exchange Server 2019 Cumulative Update 14 and 15, and Exchange Server Subscription Edition RTM.
Exploitation of this vulnerability could lead to unauthorized spoofing of email addresses, specifically altering the '5322.From' address that users see.
Users can download the security update for Microsoft Exchange Server 2016 Cumulative Update 23, Exchange Server 2019 Cumulative Update 14 and 15, and Exchange Server Subscription Edition RTM. For Exchange Server 2016 and 2019, those not enrolled in the Extended Security Update program should migrate to Exchange Server Subscription Edition to continue receiving updates.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.