Impact
A weakness in the authorization logic of Microsoft Exchange Server can allow an attacker that has authenticated network access to gain higher privileges than intended. The flaw is recognized as CWE-1390 and could enable the attacker to perform actions as a system administrator or other privileged user, compromising confidentiality, integrity, and availability of mail services.
Affected Systems
Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 14, Microsoft Exchange Server 2019 Cumulative Update 15, Microsoft Exchange Server Subscription Edition RTM are affected. Users of these versions should verify which cumulative update applies to their installation.
Risk and Exploitability
The CVSS base score of 8.8 indicates a high impact risk, and the EPSS score is unavailable, suggesting limited publicly known exploitation data. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector requires the attacker to be authenticated on the network, then exploit the weak authorization check to elevate privileges. No further conditions appear to be required.
OpenCVE Enrichment