PT-2025-32193 · Microsoft · Exchange Server
Dirk-Jan Mollema
+1
·
Published
2025-04-18
·
Updated
2025-11-15
·
CVE-2025-53786
CVSS v3.1
8.0
8.0
High
| Base vector | Vector | AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Exchange Server versions prior to the April 2025 Hot Fix
Description
A critical vulnerability (CVE-2025-53786) exists in Microsoft Exchange Server hybrid deployments. This flaw allows attackers with administrative access to on-premises Exchange servers to escalate privileges and potentially compromise cloud environments. The vulnerability stems from a shared service principal used between on-premises and Exchange Online, enabling attackers to forge trusted tokens for cloud access without generating logs. Over 29,000 Exchange servers were reported as unpatched, posing a significant risk. CISA issued an emergency directive mandating federal agencies to patch the vulnerability by August 11, 2025. The vulnerability allows for silent cloud access and potential domain compromise.
Recommendations
Apply the April 2025 Hot Fix or later to all affected Exchange Server deployments.
Implement the changes outlined in the April 18, 2025, Microsoft security guidance.
For hybrid deployments, reconfigure to use a dedicated hybrid application instead of the shared service principal.
Reset service principal credentials.
Run the Exchange Health Checker to verify the configuration.
Fix
RCE
LPE
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
dbugs@ptsecurity.com
Weakness Enumeration
Related Identifiers
BDU:2025-09477
CVE-2025-53786
Affected Products
Exchange Server
References · 213
- https://nvd.nist.gov/vuln/detail/CVE-2025-53786 · Security Note
- https://bdu.fstec.ru/vul/2025-09477 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-53786 · Security Note
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53786 · Vendor Advisory
- https://t.me/msrcreports/2095 · Telegram Post
- https://twitter.com/shah_sheikh/status/1953465004809728018 · Twitter Post
- https://twitter.com/TweetThreatNews/status/1953468370864521660 · Twitter Post
- https://twitter.com/EpicPlain/status/1953298473643598222 · Twitter Post
- https://twitter.com/sequretek_sqtk/status/1953806617528426960 · Twitter Post
- https://twitter.com/CCBalert/status/1953504500058067240 · Twitter Post
- https://twitter.com/CISACyber/status/1953251518359929253 · Twitter Post
- https://twitter.com/TweetThreatNews/status/1953629431030853982 · Twitter Post
- https://twitter.com/techpio_team/status/1970571468980290004 · Twitter Post
- https://twitter.com/NRG_fx/status/1954251099768225833 · Twitter Post
- https://twitter.com/socradar/status/1954801171073229053 · Twitter Post