CyberzSOC

Publication detail
← Back to advisories & guidance

2025-030: High Severity Vulnerability in Microsoft Exchange ↗ source

August 8, 2025 CERT-EU Advisory

Summary

The vulnerability tracked as CVE-2025-53786 allows an attacker with administrative access to an on-premises Exchange Server to escalate privileges into the connected Exchange Online environment. The vulnerability can impact the confidentiality, integrity, and availability of affected systems. An attacker with admin privileges on an on-premise Exchange server can potentially forge or manipulate trusted tokens or API calls that the cloud side will accept as legitimate. This technique allows the attackers to spread laterally from the local network into the organisation’s cloud environment, potentially compromising the organisation’s entire active directory and infrastructure [6]. The vulnerability affects the following Microsoft Exchange Servers in Hybrid Exchange Deployments: It is strongly recommended to apply the follow the vendor guidance [1]: but no longer use it), review Microsoft’s Service Principal Clean-Up Mode [4] for guidance on resetting the service principal’s keyCredentials .

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2025-53786 8.0 High Microsoft Microsoft Exchange Server 2016 Cumulative Update 23 On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.