5.3
CVE-2025-25006
- EPSS 0.85%
- Veröffentlicht 12.08.2025 17:09:53
- Zuletzt bearbeitet 15.06.2026 19:18:39
- Erkennungen
Microsoft Exchange Server Spoofing Vulnerability
Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Exchange Server Version 2016 Update -
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_1
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_10
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_11
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_12
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_13
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_14
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_15
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_16
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_17
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_18
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_19
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_2
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_20
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_21
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_3
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_4
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_5
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_6
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_7
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_8
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_9
Microsoft ≫ Exchange Server Version 2019 Update -
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_1
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_10
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_11
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_12
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_13
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_2
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_3
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_4
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_5
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_6
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_7
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_8
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_9
Microsoft ≫ Exchange Server Subscription Edition Version < 15.02.2562.020
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.85% | 0.547 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Microsoft | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
|
CWE-167 Improper Handling of Additional Special Element
The product receives input from an upstream component, but it does not handle or incorrectly handles when an additional unexpected special element is provided.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-25006