Information Disclosure Vulnerability in Microsoft Exchange Server
CVE-2025-33051

7.5HIGH

What is CVE-2025-33051?

An information disclosure vulnerability exists in Microsoft Exchange Server that enables unauthorized actors to access sensitive information over a network. This flaw can lead to the exposure of confidential data, posing a significant risk to enterprises relying on this platform for communications. Organizations must take immediate action to mitigate potential threats associated with this vulnerability.

Affected Version(s)

Microsoft Exchange Server 2016 Cumulative Update 23 x64-based Systems 15.01.0 < 15.01.2507.058

Microsoft Exchange Server 2019 Cumulative Update 14 x64-based Systems 15.02.0.0 < 15.02.1544.033

Microsoft Exchange Server 2019 Cumulative Update 15 x64-based Systems 15.02.0 < 15.02.1748.036

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-33051 : Information Disclosure Vulnerability in Microsoft Exchange Server