Impact
An incorrect authorization check in Microsoft Exchange Online allows an attacker who already has valid credentials to elevate his or her privileges. The flaw is specifically tied to an authorization misconfiguration (CWE-863) that permits a higher level of access than intended for that user. The description does not state any additional capabilities beyond the privilege increase, and no specific remote execution or data exfiltration is mentioned.
Affected Systems
Microsoft Exchange Online is affected. No version or detailed product variations are listed in the current data.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8, indicating a high severity. The EPSS score is less than 1%, suggesting a low probability of exploitation. It is not included in the CISA KEV catalog. The likely attack route is over the network, where an authenticated attacker can exploit the authorization flaw to raise privileges.
OpenCVE Enrichment