Impact
Microsoft Exchange Online is vulnerable to a server‑side request forgery (SSRF) that allows an unauthenticated attacker to elevate privileges across the network. This flaw is a CWE-918 vulnerability, rated as CVSS 10, and permits the attacker to bypass authentication controls, access privileged endpoints, and potentially execute arbitrary actions within the tenant. This can lead to full compromise of the organization’s email and collaboration services.
Affected Systems
The affected product is Microsoft Exchange Online. No specific version information was provided, so all instances of Exchange Online are potentially vulnerable until Microsoft releases a fix.
Risk and Exploitability
The CVSS score of 10 indicates that the vulnerability is critical. EPSS data is not available, but because the flaw is a SSRF that enables privilege escalation, the likelihood of exploitation remains high. While the vulnerability is not yet listed in the CISA KEV catalog, the absence of that designation does not reduce its risk. Attackers can induce Exchange Online to make outbound requests to arbitrary internal or external hosts, which the server then uses to reach privileged internal interfaces. By controlling the payload of those requests, an attacker can impersonate a privileged user and gain elevated rights.
OpenCVE Enrichment