Content:
Forwarded from Taiwan Computer Network Emergency Response Team/Coordination Center TWCERTCC-200-202510-00000009
Microsoft has issued a major security vulnerability advisory for its Exchange Server product (CVE-2025-59249, CVSS: 8.8). This vulnerability is a weak authentication vulnerability that allows an authenticated attacker to elevate privileges over the network.
Affected Platforms:
Microsoft Exchange Server Subscription Edition RTM
Microsoft Exchange Server 2019 Cumulative Update 15
Microsoft Exchange Server 2019 Cumulative Update 14
Microsoft Exchange Server 2016 Cumulative Update 23
Recommended Action:
References:
Computer and Communications Center
Network Systems Group