CVE-2025-53786
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-08-06

Last updated on: 2026-02-27

Assigner: Microsoft Corporation

Description
On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following further investigation, Microsoft identified specific security implications tied to the guidance and configuration steps outlined in the April announcement. Microsoft is issuing CVE-2025-53786 to document a vulnerability that is addressed by taking the steps documented with the April 18th announcement. Microsoft strongly recommends reading the information, installing the April 2025 (or later) Hot Fix and implementing the changes in your Exchange Server and hybrid environment.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-08-06
Last Modified
2026-02-27
Generated
2026-05-06
AI Q&A
2025-08-06
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 4 associated CPEs
Vendor Product Version / Range
microsoft exchange_server 2016
microsoft exchange_server 2019
microsoft exchange_server *
microsoft exchange_server 2019
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability relates to security implications in Microsoft Exchange Server hybrid deployments following the security changes announced on April 18th, 2025. It involves specific risks tied to the guidance and configuration steps from that announcement. Microsoft addressed this vulnerability through a Hot Fix and recommended configuration changes to improve the security of hybrid Exchange environments.


How can this vulnerability impact me? :

The vulnerability has a high severity with a CVSS base score of 8.0, indicating it can lead to significant impacts including high confidentiality, integrity, and availability losses in Exchange Server hybrid deployments if not addressed. It requires network attack with high privileges and can affect the security of your hybrid Exchange environment.


What immediate steps should I take to mitigate this vulnerability?

To mitigate this vulnerability, you should read the information provided in Microsoft's April 18th, 2025 announcement, install the April 2025 (or later) Hot Fix for Exchange Server, and implement the recommended security changes for hybrid Exchange deployments as documented in that announcement.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart