Impact
User interface misrepresentation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. The flaw misrepresents critical information, which could lead administrators and users to accept false data or be misled by the altered interface. While the CVE text does not explicitly state that attackers can acquire credentials, it is inferred that the spoofing could facilitate convincing a user to act on fabricated information, potentially enabling unauthorized actions.
Affected Systems
Microsoft Exchange Server 2016 with Cumulative Update 23, Microsoft Exchange Server 2019 with Cumulative Updates 14 and 15, and Microsoft Exchange Server Subscription Edition Release To Manufacturing are affected by the flaw.
Risk and Exploitability
The CVSS score is 5.3, indicating moderate severity, and the EPSS score of less than 1% shows a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to deliver a spoofed interface element over the network to a user; this likely requires social engineering or trust in the altered UI, making exploitation difficult. Overall risk remains moderate but active exploitation is currently unreported.
OpenCVE Enrichment