Impact
The vulnerability is a server‑side request forgery (SSRF) that occurs within Microsoft Exchange Online. An attacker who already has authorized access can craft malicious requests that force the Exchange server to initiate outbound connections, effectively bypassing normal access controls. This flaw allows the attacker to elevate privileges across the network, potentially gaining full administrative rights or accessing protected resources.
Affected Systems
Microsoft Exchange Online is affected. The specific product is Microsoft Exchange Online within the Microsoft 365 ecosystem. The CNA does not provide explicit version information, so affected workloads include any Exchange Online deployment that has not yet applied the latest available update.
Risk and Exploitability
The CVSS score of 9.9 indicates critical severity. The EPSS score of less than 1 percent suggests low current exploitation probability, and the vulnerability is not yet listed in the CISA KEV catalog. Based on the description, the likely attack vector is internal or privileged users exploiting the SSRF from within the Exchange server environment. The attacker needs authorized access to issue the malicious request; no publicly exploitable remote entry point is described.
OpenCVE Enrichment