#VU113714 Improper authentication in Microsoft Exchange Server - CVE-2025-53786
Published: August 6, 2025
Microsoft Exchange Server
Microsoft
Description
The vulnerability allows a remote attacker to escalate privileges in hybrid deployments.
The vulnerability exists due to improper authentication. A remote user with privileged access to an on-premises Exchange server can escalate privileges within the organization’s connected cloud environment without leaving easily detectable and auditable trace.