Impact
Server‑side request forgery in Microsoft Exchange Server permits an attacker who already has authorized access to fabricate requests that the server will forward to internal network resources. The vulnerability, identified by CWE‑918, can be exploited to acquire data from systems that are not exposed externally, potentially enabling further lateral movement or data exfiltration. The impact is confined to the scope of the authenticated user’s permissions, but can lead to unwanted otherwise inaccessible network endpoints being reached.
Affected Systems
This flaw affects Microsoft Exchange Server versions 2016 CU23, 2019 CU14, 2019 CU15, and the Subscription Edition released at RTM. All listed products are affected by the SSRF flaw and require the respective cumulative update to be applied.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. No EPSS value is provided and the vulnerability is not listed in CISA’s KEV catalog, suggesting that widespread exploitation has not been observed to date. The attack requires the attacker to have valid credentials and the ability to send requests through the Exchange server; thus, privileged internal users constitute a potential threat vector. While the exploit is not ultra‑common, the typical SSA technique can be used in targeted attacks to bypass perimeter defenses.
OpenCVE Enrichment