Impact
Improper authentication in Microsoft Exchange Online allows an attacker to bypass normal login controls (CWE‑287) and tamper with the service. The flaw enables unauthorized modification of email data, configuration settings, or other managed objects, potentially compromising confidentiality, integrity, and availability for the tenant.
Affected Systems
The product is Microsoft Exchange Online. No specific version range is supplied, so all deployments of Microsoft Exchange Online are potentially affected until Microsoft releases the formal fix.
Risk and Exploitability
The CVSS score of 10 signals critical severity, while the EPSS score of <1% indicates that, at the time of this analysis, the likelihood of exploitation is very low. The vulnerability is not listed in CISA KEV. The likely attack vector is remote network access, exploiting an authentication bypass to gain tampering capabilities. An attacker would send crafted authentication requests to Exchange Online, thereby manipulating messages or settings without proper authorization.
OpenCVE Enrichment