PT-2025-32193 · Microsoft · Exchange Server
Dirk-Jan Mollema
+1
·
Published
2025-04-18
·
Updated
2025-08-13
·
CVE-2025-53786
8.0
High
Base vector | Vector | AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
**Name of the Vulnerable Software and Affected Versions:**
Microsoft Exchange Server versions prior to the April 2025 Hot Fix.
**Description:**
A high-severity vulnerability exists in Microsoft Exchange Server hybrid deployments that could allow an attacker with administrative access to an on-premises Exchange server to escalate privileges and potentially compromise cloud environments. The vulnerability allows attackers to bypass authentication mechanisms and gain unauthorized access to Exchange Online. Exploitation may not generate logs, making detection difficult. Over 29,000 Exchange servers were reported as unpatched and vulnerable as of August 7, 2025. CISA issued an emergency directive mandating federal agencies to patch the vulnerability by August 11, 2025.
**Recommendations:**
Apply the April 2025 (or later) Hot Fix and implement the changes documented in the April 18th, 2025 announcement. If you are running hybrid Exchange, rearchitect identity boundaries. Reset service principal credentials and run the Exchange Health Checker. If you are using hybrid Exchange solely for SMTP relay, recipient management, and migrations, run the mitigation script.
Fix
RCE
LPE
Improper Authentication
Weakness Enumeration
Related Identifiers
Affected Products
References · 178
- https://nvd.nist.gov/vuln/detail/CVE-2025-53786 · Security Note
- https://bdu.fstec.ru/vul/2025-09477 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-53786 · Security Note
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53786 · Vendor Advisory
- https://twitter.com/TheCyberSecHub/status/1953476539355677148 · Twitter Post
- https://twitter.com/allaboutclait/status/1953536787365904479 · Twitter Post
- https://twitter.com/jcastanedacano/status/1955149893447626965 · Twitter Post
- https://twitter.com/Prevent_Cyber/status/1953688219218063650 · Twitter Post
- https://twitter.com/Forbes/status/1953423548703273279 · Twitter Post
- https://twitter.com/VaultEdgeIT/status/1953437239205077211 · Twitter Post
- https://t.me/pentestingnews/66011 · Telegram Post
- https://reddit.com/r/CVEWatch/comments/1mo4lrl/top_10_trending_cves_12082025 · Reddit Post
- https://twitter.com/fridaysecurity/status/1954012750608535941 · Twitter Post
- https://reddit.com/r/SecOpsDaily/comments/1mlsp95/cisa_orders_fed_agencies_to_patch_new_exchange · Reddit Post
- https://reddit.com/r/exchangeserver/comments/1mo0hvc/having_issues_installing_exchange_2016_cu23 · Reddit Post