Impact
The vulnerability allows an authorized attacker to disclose information over a network. This flaw enables users with valid credentials to access data beyond their intended scope, potentially revealing confidential information. The weakness maps to CWE‑285 improper access control and CWE‑918 internal resource access misconfiguration.
Affected Systems
Microsoft Exchange Server 2016 cumulative update 23, Microsoft Exchange Server 2019 cumulative update 14, Microsoft Exchange Server 2019 cumulative update 15, and Microsoft Exchange Server Subscription Edition RTM are affected per Microsoft.
Risk and Exploitability
The flaw requires an attacker to have valid credentials; the typical attack surface is within the same internal network or via a compromised account, but may also be used remotely over any network that can reach the Exchange service. The EPSS score of <1% indicates a very low probability of exploitation; however the CVSS score of 8.1 emphasizes a significant confidentiality impact if privileged accounts are not tightly controlled. The vulnerability does not appear in the CISA KEV catalog and no public exploitation has been documented. The likely attack vector is remote, as the information can be disclosed over a network, inferred from the description.
OpenCVE Enrichment