PT-2025-39523 · Pexip · Infinity+1
Published
2025-09-26
·
Updated
2025-12-25
·
CVE-2025-59683
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Pexip Infinity versions 15.0 through 38.0
Description
The Pexip Infinity software contains an issue with Improper Access Control in the Secure Scheduler for Exchange service when used with Office 365 Legacy Exchange Tokens. This allows a remote attacker to read potentially sensitive data and excessively consume resources, potentially leading to a denial of service. The issue is actively exploited.
Recommendations
Update to Pexip Infinity version 38.1 or later.
Fix
DoS
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Infinity
Pexip Infinity