Impact
Missing authorization in Microsoft Exchange Online permits an attacker who already has a valid account to gain higher privileges. This flaw can result in the attacker accessing sensitive mailbox data, executing commands, or modifying configurations, effectively compromising confidentiality, integrity, and availability of the service. The weakness corresponds to CWE‑862.
Affected Systems
The affected product is Microsoft Exchange Online. Specific version details are not disclosed, so any installation of the service remains potentially vulnerable until mitigated.
Risk and Exploitability
The CVSS score of 9.6 indicates critical severity. Exploitation requires an authenticated user inside the Exchange environment, suggesting that insiders or compromised credentials could leverage the flaw. The EPSS score is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog, but its high CVSS still raises a significant risk of privilege escalation if left unpatched.
OpenCVE Enrichment