7.5

CVE-2025-33051

Microsoft Exchange Server Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Exchange Server Version 2016 Update -
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_1
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_10
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_11
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_12
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_13
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_14
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_15
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_16
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_17
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_18
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_19
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_2
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_20
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_21
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_22
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_3
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_4
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_5
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_6
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_7
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_8
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_9
Microsoft ≫ Exchange Server Version 2019 Update -
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_1
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_10
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_11
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_12
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_13
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_2
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_3
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_4
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_5
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_6
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_7
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_8
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_9
Microsoft ≫ Exchange Server Subscription Edition Version < 15.02.2562.020
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.23% 0.659
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Microsoft 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-33051
Vendor Advisory