Impact
The vulnerability arises from improper handling of resource identifiers—essentially a resource injection flaw—in Microsoft Exchange Server. An attacker with legitimate network access can craft requests that manipulate these identifiers, enabling them to elevate their privileges beyond what is normally permitted. Because the flaw does not require remote code execution or additional authentication, compromised accounts can gain administrative control over the Exchange environment.
Affected Systems
Affected are Microsoft Exchange Server 2016 Cumulative Update 23, Exchange Server 2019 Cumulative Update 14 and 15, and Microsoft Exchange Server Subscription Edition Release to Manufacturing. All installations that have not applied the listed cumulative updates remain vulnerable.
Risk and Exploitability
The CVSS score of 7.2 categorizes the issue as moderate to high severity. EPSS data is currently unavailable and the vulnerability is not yet cataloged in CISA KEV, indicating limited widespread exploitation reports. The likely attack vector is an authorized adversary who can submit crafted requests to the Exchange server; the flaw does not rely on internet-facing exposure. Exploitation achieves privilege escalation, potentially giving an attacker control over the entire server and the likelihood of further compromise is high once elevated privileges are obtained.
OpenCVE Enrichment