Impact
The vulnerability is a missing authorization check that enables an authenticated attacker to elevate privileges within Microsoft Exchange Server. With appropriate credentials or an active session, the attacker can exercise higher levels of access, potentially reading, modifying, or deleting sensitive data and configuration settings. This weakness is classified as CWE-862, missing authorization.
Affected Systems
Affected products include Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 14, Microsoft Exchange Server 2019 Cumulative Update 15, and Microsoft Exchange Server Subscription Edition RTM. All builds that incorporate these specific updates are vulnerable.
Risk and Exploitability
The CVSS score of 9.1 indicates a critical severity. The EPSS score is < 1%, suggesting a low but nonzero chance of exploitation. The flaw is not listed in CISA KEV, which indicates no known publicly available exploits. The vulnerability requires an attacker to already possess valid credentials or an authenticated session to the Exchange environment. Once authenticated, the missing authorization logic can be leveraged to elevate privileges, potentially giving access to the entire organization’s mailbox data, policy settings, and server configurations.
OpenCVE Enrichment