Impact
The vulnerability is a missing authorization check that permits an authenticated user to bypass a security feature across the network. This flaw can allow an attacker who already has some level of access to perform actions that should be restricted, potentially exposing privileged functions or data to unauthorized use. The weakness falls under Improper Authorization (CWE‑862) and could be leveraged to compromise the integrity and confidentiality of the Exchange environment if the attacker already possesses elevated permissions.
Affected Systems
Microsoft has identified several affected releases of Microsoft Exchange Server: version 2016 with Cumulative Update 23, version 2019 with Cumulative Updates 14 and 15, and the Subscription Edition at Release To Manufacturing (RTM). These are the only product versions explicitly listed as impacted; no other Exchange Server releases or update states are noted.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at the present time. The vulnerability is not catalogued in the CISA KEV list, and no active exploit references are publicly known. Exploitation requires a network‑based approach from an authenticated user, which is inferred from the description that the bypass occurs over a network. Administrators should treat this as a moderate risk that warrants timely remediation.
OpenCVE Enrichment