Impact
The vulnerability is an authorization bypass that allows an attacker with legitimate credentials to supply a user-controlled key and alter configuration or data on a Microsoft Exchange Server. This flaw, classified as CWE-639, enables tampering of system settings and potentially sensitive information without proper authorization.
Affected Systems
Affected systems include Microsoft Exchange Server 2016 updated to Cumulative Update 23, Microsoft Exchange Server 2019 updated to Cumulative Update 14 or 15, and Microsoft Exchange Server Subscription Edition Release to Market. Administrators should check these specific builds for the vulnerability.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires the attacker to be authenticated on the network; they can then manipulate the key to bypass authorization and perform tampering actions. Because of the network exposure, defenders should treat this as a potential privileged abuse scenario.
OpenCVE Enrichment