Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-53786— Microsoft Exchange Server Hybrid Deployment Elevation of Privilege Vulnerability

CVSS 8.0 · High EPSS 0.26% · P49
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-53786

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Microsoft Exchange Server Hybrid Deployment Elevation of Privilege Vulnerability
Source: NVD (National Vulnerability Database)
Vulnerability Description
On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following further investigation, Microsoft identified specific security implications tied to the guidance and configuration steps outlined in the April announcement. Microsoft is issuing CVE-2025-53786 to document a vulnerability that is addressed by taking the steps documented with the April 18th announcement. Microsoft strongly recommends reading the information, installing the April 2025 (or later) Hot Fix and implementing the changes in your Exchange Server and hybrid environment.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
认证机制不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
Microsoft Exchange Server 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Microsoft Exchange Server是美国微软(Microsoft)公司的一套电子邮件服务程序。它提供邮件存取、储存、转发,语音邮件,邮件过滤筛选等功能。 Microsoft Exchange Server存在授权问题漏洞,该漏洞源于混合部署配置不当,可能导致安全风险。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
MicrosoftMicrosoft Exchange Server 2016 Cumulative Update 23 15.01.0.0 ~ 15.01.2507.055 -
MicrosoftMicrosoft Exchange Server 2019 Cumulative Update 14 15.02.0.0 ~ 15.02.1544.025 -
MicrosoftMicrosoft Exchange Server 2019 Cumulative Update 15 15.02.0.0 ~ 15.02.1748.024 -
MicrosoftMicrosoft Exchange Server Subscription Edition RTM 15.02.0.0 ~ 15.02.2562.017 -

II. Public POCs for CVE-2025-53786

#POC DescriptionSource LinkShenlong Link
1Nonehttps://github.com/barbaraeivyu/CVE-2025-53786POC Details
2Nonehttps://github.com/vincentdthe/CVE-2025-53786POC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-53786

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2025-53786

No comments yet


Leave a comment