CVE-2025-25006 is a medium-severity spoofing vulnerability in Microsoft Exchange Server, stemming from improper handling of a special element. This network-based vulnerability requires no user interaction or privileges, allowing an unauthenticated attacker to achieve low integrity impact. While not actively exploited (KEV: No) and lacking public exploit code (Metasploit, Nuclei, ExploitDB: None), it has garnered some community and media attention, with one article noting its inclusion in a future Microsoft Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2016:-:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_1:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_10:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_11:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_12:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.