Home
HIGH: 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 15.02.0.0 (custom) before 15.02.1748.042
affected
15.01.0.0 (custom) before 15.01.2507.063
affected
15.02.0.0 (custom) before 15.02.2562.035
affected
15.02.0.0 (custom) before 15.02.1544.037
affected
Description
Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Problem types
CWE-20: Improper Input Validation
Product status
References
msrc.microsoft.com/update-guide/vulnerability/CVE-2025-64666 (Microsoft Exchange Server Elevation of Privilege Vulnerability)