Impact
Improper neutralization of input during web page generation allows an attacker to inject malicious content that the Exchange Server renders. The vulnerability is a cross‑site scripting flaw (CWE‑79) with a CVSS score of 9.3, indicating a high‑severity risk that can lead to unauthorized identity impersonation. The attack can compromise confidentiality by enabling an attacker to present themselves as a legitimate user and potentially gain access to sensitive information or perform further malicious actions.
Affected Systems
Affected are Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 14, Microsoft Exchange Server 2019 Cumulative Update 15, and the Subscription Edition released to the RTM version. These deployments are listed with their corresponding update identifiers in the official Microsoft advisory.
Risk and Exploitability
The flaw is exploitable via the Exchange web interface or any component that renders user‑supplied data into a page. The lack of an available EPSS score and absence from the CISA KEV catalog suggest that exploit activity is not widely observed, yet the high CVSS score and the ability to spoof users create a significant threat if the vulnerability is leveraged. An attacker with network access to the Exchange environment can craft a malicious request that triggers the vulnerability, resulting in spoofed identities and potential privilege escalation.
OpenCVE Enrichment