Impact
An attacker who already possesses valid Exchange Server credentials can exploit a missing authorization check to increase their privileges. Because the flaw does not require external network exposure, the attack can be executed from any internal or compromised network node that can reach the Exchange instance. The effect of the weak check is an elevation of privilege that could enable the attacker to run arbitrary commands, read confidential data, or tamper with server configuration, thereby compromising confidentiality, integrity, and availability of the Exchange environment.
Affected Systems
The vulnerability affects Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 14, Microsoft Exchange Server 2019 Cumulative Update 15, and Microsoft Exchange Server Subscription Edition RTM. Each affected release has a known missing authorization guard that can be triggered with existing authenticated privileges.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity threat. The EPSS score is not available, and the vulnerability is not listed in CISA Kev. Attackers need legitimate credentials but do not require higher privileges or special network access; the exploit can be performed within a normal network segment where the Exchange Server is reachable, implying a moderate to high likelihood of exploitation once credentials are compromised. The vulnerability is therefore considered a significant risk to organizations with unpatched Exchange installations.
OpenCVE Enrichment