CVE-2025-53782Incorrect Implementation of Authentication Algorithm in Microsoft Exchange Server 2016 Cumulative Update 23

Severity
7.8HIGHNVD
CNA8.4
EPSS
0.1%
top 79.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 14

Description

Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages5 packages

NVDmicrosoft/exchange_server< 15.02.2562.029+2
CVEListV5microsoft/microsoft_exchange_server_subscription_edition_rtm15.02.0.015.02.2562.029

🔴Vulnerability Details

2
CVEList
Microsoft Exchange Server Elevation of Privilege Vulnerability2025-10-14
GHSA
GHSA-2jpf-9r3f-f5p3: Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally2025-10-14

📋Vendor Advisories

1
Microsoft
Microsoft Exchange Server Elevation of Privilege Vulnerability2025-10-14
CVE-2025-53782 — Microsoft vulnerability | cvebase