Impact
Server‑side request forgery (SSRF) in Microsoft Exchange Server creates a flaw that allows an authorized attacker to elevate privileges over a network. The vulnerability arises when the server accepts a crafted request from an attacker who already possesses some level of access to the system, causing the server to forward requests to internal resources, thereby granting the attacker higher privileges than originally granted. The weakness is categorized as CWE‑918, which highlights the risk of SSRF leading to privilege escalation and unintended resource access. Based on the description, the SSRF flaw causes the server to forward requests to internal resources, which is inferred.
Affected Systems
Microsoft Exchange Server 2016 cumulative update 23, Microsoft Exchange Server 2019 cumulative updates 14 and 15, and Microsoft Exchange Server Subscription Edition RTM are affected. These releases represent the specific versions of Exchange Server that contain the SSRF flaw. Organizations using any of these deployments should verify which update level they are running and proceed accordingly.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate risk, and the EPSS score is not available, so the current estimation of exploitation probability cannot be determined from this data. The vulnerability is not listed in the CISA KEV catalog, suggesting that no widely reported exploits have been seen yet. Nevertheless, because the SSRF flaw requires an attacker to already have some authorized access, it is inferred that the attack vector is likely internal or via compromised credentials. If an attacker can send crafted requests to internal Exchange components, they may be able to obtain elevated permissions, potentially compromising the entire organization. Based on the description, this inference is derived from the documented behavior of SSRF in the affected product.
OpenCVE Enrichment