Reported by TechRadar, the vulnerability could allow attackers who already have valid login credentials to increase their privileges within Exchange and access mailboxes belonging to other users. Microsoft released the fix on October 2, ahead of its originally intended schedule.
About the flaw
The security issue stems from a weakness in authorization controls, which determine what information a user can access. By exploiting the flaw over a network, an authenticated attacker could gain permissions beyond those assigned to their account.
Threat actors could first obtain credentials through phishing attacks or by purchasing stolen login details from underground online markets. Once inside an organization’s Exchange environment, they could exploit the vulnerability to read emails and attachments belonging to other employees.
However, the flaw does not provide unrestricted access across different customer environments, known as tenants. It also does not directly grant administrator-level or SYSTEM-level privileges on the underlying Windows server.
What happens in case of successful exploitation?
Successful exploitation could expose sensitive business information, including financial records, invoices, contracts, customer correspondence, internal discussions, and confidential documents.
Attackers could use the stolen information to support further cyberattacks. For example, they might impersonate company employees, send convincing fraudulent emails, or conduct business email compromise (BEC) scams to trick organizations into transferring money or disclosing additional information.
The vulnerability is particularly problematic because an ordinary employee’s compromised account could potentially provide an entry point for accessing information held in other employees’ mailboxes.
Affected products
The vulnerability affects the following on-premises products:
- Microsoft Exchange Server Subscription Edition RTM
- Microsoft Exchange Server 2016 Cumulative Update 23
- Microsoft Exchange Server 2019 Cumulative Updates 14 and 15
Microsoft has confirmed that Exchange Online customers are protected by a server-side fix. Organizations running affected on-premises installations should install the appropriate security updates promptly.
Exchange Server 2016 and 2019 have reached the end of their standard support lifecycle. Eligible organizations must be enrolled in Microsoft’s Extended Security Update programme to receive the relevant updates for these versions. Microsoft recommends that organizations without the required coverage migrate to Exchange Server Subscription Edition.
Microsoft’s response
Microsoft reported no evidence that the vulnerability was being actively exploited at the time of the report. However, the company assessed that exploitation was more likely, making timely patching important.
Administrators should run Microsoft’s Exchange Server Health Checker after installing the update to verify successful deployment and identify any additional actions required.