Impact
The vulnerability is caused by an uncontrolled recursion in Microsoft Exchange Server. An attacker who can send specially crafted network requests may trigger unlimited recursion that exhausts system resources. This results in a denial of service that can affect message routing services, making the Exchange server unavailable to legitimate users and degrading service availability.
Affected Systems
Affected products include Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 14, Microsoft Exchange Server 2019 Cumulative Update 15, and the Microsoft Exchange Server Subscription Edition at release. These vulnerabilities were identified in the specific cumulative updates listed in the Microsoft release guide and SKU. Users deploying these versions should verify the build.
Risk and Exploitability
The CVSS score of 7.5 indicates a high impact denial of service that does not compromise confidentiality or integrity. The EPSS score is 1%, but the lack of a KEV listing suggests no publicly known exploits at the time of analysis. The likely attack vector is a remote network-based request that an attacker can send without authentication. Because the flaw is in core Exchange processing logic, repeated requests can consume memory and CPU until the service stops or must be restarted.
OpenCVE Enrichment