CVE-2025-64667: Microsoft Exchange Server Spoofing Vulnerability
Published Dec 9, 2025
·Updated
Microsoft Exchange Server Spoofing Vulnerability
Other sources
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
— Microsoft
Affected Software
42 affected componentsFixes available
Microsoft Exchange Server 2019=14
Microsoft Exchange Server 2019=15
Microsoft Exchange Server Subscription Edition RTM
Microsoft Exchange Server 2016=23
Microsoft Exchange Server=2016
Microsoft Exchange Server=2016-cumulative_update_1
Microsoft Exchange Server=2016-cumulative_update_10
Microsoft Exchange Server=2016-cumulative_update_11
Microsoft Exchange Server=2016-cumulative_update_12
Microsoft Exchange Server=2016-cumulative_update_13
Microsoft Exchange Server=2016-cumulative_update_14
Microsoft Exchange Server=2016-cumulative_update_15
Microsoft Exchange Server=2016-cumulative_update_16
Microsoft Exchange Server=2016-cumulative_update_17
Microsoft Exchange Server=2016-cumulative_update_18
Microsoft Exchange Server=2016-cumulative_update_19
Microsoft Exchange Server=2016-cumulative_update_2
Microsoft Exchange Server=2016-cumulative_update_20
Microsoft Exchange Server=2016-cumulative_update_21
Microsoft Exchange Server=2016-cumulative_update_22
Microsoft Exchange Server=2016-cumulative_update_3
Microsoft Exchange Server=2016-cumulative_update_4
Microsoft Exchange Server=2016-cumulative_update_5
Microsoft Exchange Server=2016-cumulative_update_6
Microsoft Exchange Server=2016-cumulative_update_7
Microsoft Exchange Server=2016-cumulative_update_8
Microsoft Exchange Server=2016-cumulative_update_9
Microsoft Exchange Server=2019
Microsoft Exchange Server=2019-cumulative_update_1
Microsoft Exchange Server=2019-cumulative_update_10
Microsoft Exchange Server=2019-cumulative_update_11
Microsoft Exchange Server=2019-cumulative_update_12
Microsoft Exchange Server=2019-cumulative_update_13
Microsoft Exchange Server=2019-cumulative_update_2
Microsoft Exchange Server=2019-cumulative_update_3
Microsoft Exchange Server=2019-cumulative_update_4
Microsoft Exchange Server=2019-cumulative_update_5
Microsoft Exchange Server=2019-cumulative_update_6
Microsoft Exchange Server=2019-cumulative_update_7
Microsoft Exchange Server=2019-cumulative_update_8
Microsoft Exchange Server=2019-cumulative_update_9
Microsoft Exchange Server Subscription Edition<15.02.2562.035
Event History
Dec 9, 2025
CVE Published
via Microsoft·08:00 AM
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
Description
CVE Published
via MITRE·05:55 PM
Data Sourced
via MITRE·05:55 PM
DescriptionSeverity
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-64667?
CVE-2025-64667 is considered a medium severity spoofing vulnerability affecting Microsoft Exchange Server.
2
How do I fix CVE-2025-64667?
To fix CVE-2025-64667, apply the latest security update provided by Microsoft for your version of Exchange Server.
3
What versions of Microsoft Exchange Server are affected by CVE-2025-64667?
CVE-2025-64667 affects Microsoft Exchange Server 2016, 2019, and the Subscription Edition.
4
What type of attack can CVE-2025-64667 enable?
CVE-2025-64667 can enable an unauthorized attacker to perform spoofing attacks over a network.
5
Is authentication required to exploit CVE-2025-64667?
No, CVE-2025-64667 does not require authentication to exploit, making it particularly dangerous.