Impact
A flaw in the cryptographic algorithm used by Microsoft Exchange Server permits an attacker who is not authenticated to disclose sensitive information over a network. The vulnerability is caused by a broken or risky cryptographic implementation that can be triggered from an external connection.
Affected Systems
Microsoft Exchange Server 2016 with Cumulative Update 23, Exchange Server 2019 with Cumulative Updates 14 and 15, and Exchange Server Subscription Edition RTM are specified as affected. Systems running these update levels are impacted unless a newer update is installed or an alternative mitigation is applied.
Risk and Exploitability
The vulnerability has a CVSS score of 5.9, indicating moderate severity. No EPSS score is available and it is not listed in the CISA KEV catalog. Attackers can exploit the issue from a network location without authentication by interacting with Exchange services to trigger the information disclosure, but the CVE description does not provide further exploitation details.
OpenCVE Enrichment