Impact
The vulnerability is a server‑side request forgery (SSRF) that permits an authorized attacker to disclose information over a network. The flaw is an improper authorization vulnerability in Microsoft Exchange Server that allows an authenticated attacker to read data over the network. Because the weakness is a direct breach of access control (CWE‑285), an attacker who can authenticate to the Exchange Server can gain confidentiality of data not intended for that user. The CVSS score of 8.1 reflects the high confidentiality impact of this scenario.
Affected Systems
Microsoft Exchange Server 2016 cumulative update 23, Microsoft Exchange Server 2019 cumulative update 14, Microsoft Exchange Server 2019 cumulative update 15, and Microsoft Exchange Server Subscription Edition RTM are all affected, as identified by the CNA and reflected in the CVE vendor/product listings.
Risk and Exploitability
Because the attacker must possess valid credentials, the most likely attack surface is within an internal network or through a compromised account. The likely attack vector is remote, as the information can be disclosed over a network, but this inference is drawn from the description rather than an explicit statement. No known exploits appear in CISA’s KEV catalog and EPSS data is unavailable, yet the high CVSS score indicates a significant potential for confidentiality breaches if privileged accounts are not tightly controlled.
OpenCVE Enrichment