Impact
Microsoft Exchange Server suffers an authentication bypass that allows an attacker who can capture and replay authentication traffic to elevate privileges on the host. The flaw enables an authorized user or compromised network element to impersonate administrative identities, potentially gaining full control over Exchange services, data, and configurations. This weakness is identified as CWE‑294 (Elevation of Privilege), meaning that the attacker can increase access rights beyond intended scopes. Based on the description, the likely attack vector is capturing and replaying authentication traffic over the network.
Affected Systems
Affected are Microsoft Exchange Server 2016 running Cumulative Update 23, Microsoft Exchange Server 2019 running Cumulative Update 14 and 15, and Microsoft Exchange Server Subscription Edition RTM. All of these versions have the elevated privilege flaw and must be updated to a patched build.
Risk and Exploitability
The CVSS score of 8 indicates a high severity vulnerability, giving attackers opportunity to compromise system integrity. With no EPSS score available, the exact exploitation probability cannot be quantified, but the lack of listing in CISA KEV suggests no publicly known exploits at this time. Nevertheless, the high score and the fact that the flaw can be triggered via network capture and replay pose a significant risk, especially in environments where administrators have widespread network access. Prompt patching is therefore recommended to mitigate the elevated privilege threat.
OpenCVE Enrichment