CVE-2025-58107: High severity Microsoft Exchange vulnerability
In Microsoft Exchange through 2019, Exchange ActiveSync (EAS) configurations on on-premises servers may transmit sensitive data from Samsung mobile devices in cleartext, including the user's name, e-mail address, device ID, bearer token, and base64-encoded password.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58107?
CVE-2025-58107 is considered a high severity vulnerability due to the exposure of sensitive user data.
How do I fix CVE-2025-58107?
To fix CVE-2025-58107, ensure that Exchange ActiveSync configurations are updated to use secure transmission methods for sensitive data.
What data is exposed by CVE-2025-58107?
CVE-2025-58107 exposes sensitive data including the user's name, e-mail address, device ID, bearer token, and base64-encoded password.
Which versions of Microsoft Exchange are affected by CVE-2025-58107?
CVE-2025-58107 affects Microsoft Exchange on-premises versions through 2019.
What are the potential impacts of CVE-2025-58107?
The potential impacts of CVE-2025-58107 include unauthorized access to user accounts and compromise of sensitive information.