Tampering Vulnerability in Microsoft Exchange Server
CVE-2025-25005

6.5MEDIUM

What is CVE-2025-25005?

A security risk exists within Microsoft Exchange Server due to improper input validation. This vulnerability allows an authorized attacker to exploit the system and perform tampering operations over a network, thereby potentially compromising data integrity and security. Organizations leveraging Microsoft Exchange Server must remain vigilant and apply necessary patches and updates to protect against this vulnerability.

Affected Version(s)

Microsoft Exchange Server 2016 Cumulative Update 23 x64-based Systems 15.01.0 < 15.01.2507.058

Microsoft Exchange Server 2019 Cumulative Update 14 x64-based Systems 15.02.0.0 < 15.02.1544.033

Microsoft Exchange Server 2019 Cumulative Update 15 x64-based Systems 15.02.0 < 15.02.1748.036

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-25005 : Tampering Vulnerability in Microsoft Exchange Server