CVE-2025-25005: Microsoft Exchange Server Tampering Vulnerability
Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
Other sources
Microsoft Exchange Server Tampering Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25005?
CVE-2025-25005 is considered a high severity vulnerability due to the potential for authorized attackers to tamper with data over the network.
How do I fix CVE-2025-25005?
To fix CVE-2025-25005, apply the latest patches released by Microsoft for your version of Exchange Server.
Which versions of Exchange Server are affected by CVE-2025-25005?
CVE-2025-25005 affects Microsoft Exchange Server Subscription Edition RTM, Exchange Server 2016, and Exchange Server 2019.
What type of vulnerability is CVE-2025-25005?
CVE-2025-25005 is an improper input validation vulnerability that allows attackers to perform unauthorized tampering.
Who is responsible for addressing the CVE-2025-25005 vulnerability?
It is the responsibility of system administrators and organizations using the affected versions of Microsoft Exchange Server to address CVE-2025-25005.