Date Posted: 2025/10/20
[Vulnerability Alert] Microsoft Exchange Server Has a Major Security Vulnerability (CVE-2025-59249)
- Subject: [Vulnerability Alert] Microsoft Exchange Server Has a Major Security Vulnerability (CVE-2025-59249)
- Content:
- Forwarded from Taiwan Computer Network Emergency Response Team/Coordination Center TWCERTCC-200-202510-00000009
- Microsoft has issued a major security vulnerability advisory for its Exchange Server product (CVE-2025-59249, CVSS: 8.8). This vulnerability is a weak authentication vulnerability that allows an authenticated attacker to elevate privileges over the network.
- Affected Platforms:
- Microsoft Exchange Server Subscription Edition RTM
- Microsoft Exchange Server 2019 Cumulative Update 15
- Microsoft Exchange Server 2019 Cumulative Update 14
- Microsoft Exchange Server 2016 Cumulative Update 23
- Recommended Action:
- Apply the patch according to the solutions released on the official website: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59249
- References:
Computer and Communications Center
Network Systems Group