CVE-2025-64666: Microsoft Exchange Server Elevation of Privilege Vulnerability
Published Dec 9, 2025
·Updated
Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Other sources
Microsoft Exchange Server Elevation of Privilege Vulnerability
— Microsoft
Affected Software
42 affected componentsFixes available
Microsoft Exchange Server Subscription Edition RTM
Microsoft Exchange Server 2019=14
Microsoft Exchange Server 2019=15
Microsoft Exchange Server 2016=23
Microsoft Exchange Server=2016
Microsoft Exchange Server=2016-cumulative_update_1
Microsoft Exchange Server=2016-cumulative_update_10
Microsoft Exchange Server=2016-cumulative_update_11
Microsoft Exchange Server=2016-cumulative_update_12
Microsoft Exchange Server=2016-cumulative_update_13
Microsoft Exchange Server=2016-cumulative_update_14
Microsoft Exchange Server=2016-cumulative_update_15
Microsoft Exchange Server=2016-cumulative_update_16
Microsoft Exchange Server=2016-cumulative_update_17
Microsoft Exchange Server=2016-cumulative_update_18
Microsoft Exchange Server=2016-cumulative_update_19
Microsoft Exchange Server=2016-cumulative_update_2
Microsoft Exchange Server=2016-cumulative_update_20
Microsoft Exchange Server=2016-cumulative_update_21
Microsoft Exchange Server=2016-cumulative_update_22
Microsoft Exchange Server=2016-cumulative_update_3
Microsoft Exchange Server=2016-cumulative_update_4
Microsoft Exchange Server=2016-cumulative_update_5
Microsoft Exchange Server=2016-cumulative_update_6
Microsoft Exchange Server=2016-cumulative_update_7
Microsoft Exchange Server=2016-cumulative_update_8
Microsoft Exchange Server=2016-cumulative_update_9
Microsoft Exchange Server=2019
Microsoft Exchange Server=2019-cumulative_update_1
Microsoft Exchange Server=2019-cumulative_update_10
Microsoft Exchange Server=2019-cumulative_update_11
Microsoft Exchange Server=2019-cumulative_update_12
Microsoft Exchange Server=2019-cumulative_update_13
Microsoft Exchange Server=2019-cumulative_update_2
Microsoft Exchange Server=2019-cumulative_update_3
Microsoft Exchange Server=2019-cumulative_update_4
Microsoft Exchange Server=2019-cumulative_update_5
Microsoft Exchange Server=2019-cumulative_update_6
Microsoft Exchange Server=2019-cumulative_update_7
Microsoft Exchange Server=2019-cumulative_update_8
Microsoft Exchange Server=2019-cumulative_update_9
Microsoft Exchange Server Subscription Edition<15.02.2562.035
Event History
Dec 9, 2025
CVE Published
via Microsoft·08:00 AM
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
Description
CVE Published
via MITRE·05:55 PM
Data Sourced
via MITRE·05:55 PM
DescriptionSeverity
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-64666?
CVE-2025-64666 has a severity rating that allows an authorized attacker to elevate privileges within Microsoft Exchange Server.
2
How do I fix CVE-2025-64666?
To fix CVE-2025-64666, apply the latest security updates provided by Microsoft for your version of Exchange Server.
3
Which versions of Microsoft Exchange Server are affected by CVE-2025-64666?
CVE-2025-64666 affects Microsoft Exchange Server 2016, 2019, and Subscription Edition RTM.
4
Can CVE-2025-64666 be exploited remotely?
Yes, CVE-2025-64666 can be exploited over a network, allowing an attacker to elevate privileges.
5
What type of vulnerability is CVE-2025-64666?
CVE-2025-64666 is classified as an elevation of privilege vulnerability due to improper input validation.