CVE-2025-59248: Microsoft Exchange Server Spoofing Vulnerability
Published Oct 14, 2025
·Updated
Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Other sources
Microsoft Exchange Server Spoofing Vulnerability
— Microsoft
Affected Software
42 affected componentsFixes available
Microsoft Exchange Server 2019=15
Microsoft Exchange Server 2016=23
Microsoft Exchange Server 2019=14
Microsoft Exchange Server Subscription Edition RTM
Microsoft Exchange Server=2016
Microsoft Exchange Server=2016-cumulative_update_1
Microsoft Exchange Server=2016-cumulative_update_10
Microsoft Exchange Server=2016-cumulative_update_11
Microsoft Exchange Server=2016-cumulative_update_12
Microsoft Exchange Server=2016-cumulative_update_13
Microsoft Exchange Server=2016-cumulative_update_14
Microsoft Exchange Server=2016-cumulative_update_15
Microsoft Exchange Server=2016-cumulative_update_16
Microsoft Exchange Server=2016-cumulative_update_17
Microsoft Exchange Server=2016-cumulative_update_18
Microsoft Exchange Server=2016-cumulative_update_19
Microsoft Exchange Server=2016-cumulative_update_2
Microsoft Exchange Server=2016-cumulative_update_20
Microsoft Exchange Server=2016-cumulative_update_21
Microsoft Exchange Server=2016-cumulative_update_22
Microsoft Exchange Server=2016-cumulative_update_3
Microsoft Exchange Server=2016-cumulative_update_4
Microsoft Exchange Server=2016-cumulative_update_5
Microsoft Exchange Server=2016-cumulative_update_6
Microsoft Exchange Server=2016-cumulative_update_7
Microsoft Exchange Server=2016-cumulative_update_8
Microsoft Exchange Server=2016-cumulative_update_9
Microsoft Exchange Server=2019
Microsoft Exchange Server=2019-cumulative_update_1
Microsoft Exchange Server=2019-cumulative_update_10
Microsoft Exchange Server=2019-cumulative_update_11
Microsoft Exchange Server=2019-cumulative_update_12
Microsoft Exchange Server=2019-cumulative_update_13
Microsoft Exchange Server=2019-cumulative_update_2
Microsoft Exchange Server=2019-cumulative_update_3
Microsoft Exchange Server=2019-cumulative_update_4
Microsoft Exchange Server=2019-cumulative_update_5
Microsoft Exchange Server=2019-cumulative_update_6
Microsoft Exchange Server=2019-cumulative_update_7
Microsoft Exchange Server=2019-cumulative_update_8
Microsoft Exchange Server=2019-cumulative_update_9
Microsoft Exchange Server Subscription Edition<15.02.2562.029
Event History
Oct 14, 2025
CVE Published
via Microsoft·07:00 AM
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
Description
Updated
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:01 PM
Data Sourced
via MITRE·05:01 PM
DescriptionSeverity
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-59248?
CVE-2025-59248 is evaluated as a critical vulnerability due to its potential for spoofing attacks on Microsoft Exchange Server.
2
How do I fix CVE-2025-59248?
To fix CVE-2025-59248, update your Microsoft Exchange Server with the latest patches provided by Microsoft.
3
Which versions of Microsoft Exchange Server are affected by CVE-2025-59248?
CVE-2025-59248 affects Microsoft Exchange Server Subscription Edition, Exchange Server 2019, and Exchange Server 2016.
4
What kind of attacks does CVE-2025-59248 enable?
CVE-2025-59248 allows unauthorized attackers to perform spoofing attacks over a network.
5
Is there a workaround for CVE-2025-59248?
There are no official workarounds for CVE-2025-59248, and applying the necessary patches is the recommended approach.