Impact
Microsoft Exchange Server has a flaw in its access control that allows an attacker who already has local access to gain higher privileges on the host. The vulnerability stems from insufficient granularity in permission checks and can enable a user to obtain administrative level rights, potentially giving them full control over the local system. This weakness is classified as CWE-1220, indicating that access control scopes are not properly enforced.
Affected Systems
The affected products are Microsoft Exchange Server 2016 with cumulative update 23, Microsoft Exchange Server 2019 with cumulative updates 14 and 15, and the Exchange Server Subscription Edition in its RTM release. These versions are susceptible to the privilege escalation flaw until patched.
Risk and Exploitability
The CVSS score of 7.8 places this vulnerability in the medium to high severity range. The EPSS score of less than 1% indicates a very low probability of exploit at this time, and the issue is not listed in the CISA KEV catalog. Because the vulnerability requires local access and insufficient permission granularity, it is likely that an attacker would first need to authenticate or gain local foothold before escalating. In environments where local accounts are privileged, the risk is amplified, but the low exploitation likelihood suggests that patching should be prioritized over monitoring alone.
OpenCVE Enrichment