cbcvebase.
CVE-2025-53782
published 2025-10-14

CVE-2025-53782: Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally.

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally.

Affected

11 ranges
VendorProductVersion rangeFixed in
microsoftexchange_server< 15.02.2562.02915.02.2562.029
microsoftexchange_server
microsoftexchange_server
microsoftmicrosoft_exchange_server_2016_cumulative_update_23>= 15.01.0.0 < 15.01.2507.06115.01.2507.061
microsoftmicrosoft_exchange_server_2019_cumulative_update_14>= 15.02.0.0 < 15.02.1544.03615.02.1544.036
microsoftmicrosoft_exchange_server_2019_cumulative_update_15>= 15.02.0.0 < 15.02.1748.03915.02.1748.039
microsoftmicrosoft_exchange_server_subscription_edition_rtm>= 15.02.0.0 < 15.02.2562.02915.02.2562.029
msrcmicrosoft_exchange_server_2016_cumulative_update_23
msrcmicrosoft_exchange_server_2019_cumulative_update_14
msrcmicrosoft_exchange_server_2019_cumulative_update_15
msrcmicrosoft_exchange_server_subscription_edition_rtm