Impact
Improper neutralization of user input during web page generation creates a classic cross‑site scripting flaw. By injecting malicious script into the HTML pages served by Microsoft Exchange Server, an attacker can have that script executed in the browsers of unsuspecting users, allowing the attacker to present forged content and impersonate the server or domain on a network.
Affected Systems
Microsoft Exchange Server 2016 with Cumulative Update 23, Microsoft Exchange Server 2019 with Cumulative Updates 14 and 15, and the Subscription Edition at release time (RTM) are listed as affected by Microsoft. These versions are included in the CNA vendor/product data and in the affected CPEs.
Risk and Exploitability
The CVSS score of 9.6 marks the flaw as critical, while the EPSS score of less than 1% indicates a very low probability of exploitation at present. The likely attack vector is a crafted web request to the Exchange Server’s remote interface. The vulnerability is not listed in the CISA KEV catalog, implying no known weaponized use. Attackers would need to send a crafted web request to a vulnerable Exchange Server’s remote interface to trigger the XSS payload, targeting the web services that generate HTML output.
OpenCVE Enrichment