← Back to advisories & guidance
August 8, 2025
CERT-EU
Advisory
Summary
The vulnerability tracked as CVE-2025-53786 allows an attacker with administrative access to an on-premises Exchange Server to escalate privileges into the connected Exchange Online environment. The vulnerability can impact the confidentiality, integrity, and availability of affected systems. An attacker with admin privileges on an on-premise Exchange server can potentially forge or manipulate trusted tokens or API calls that the cloud side will accept as legitimate. This technique allows the attackers to spread laterally from the local network into the organisation’s cloud environment, potentially compromising the organisation’s entire active directory and infrastructure [6]. The vulnerability affects the following Microsoft Exchange Servers in Hybrid Exchange Deployments: It is strongly recommended to apply the follow the vendor guidance [1]: but no longer use it), review Microsoft’s Service Principal Clean-Up Mode [4] for guidance on resetting the service principal’s keyCredentials .
News Coverage
No coverage found in monitored research blogs or news feeds.
CVEs Referenced in This Publication
Extracted from the publication text. Each CVE links to its tracked detail page.
Vendors Named in This Publication
Each vendor links to its Known Exploited Vulnerabilities catalog page.
Only vendors that appear in the KEV catalog are listed, either because
the publication cites one of their KEV entries or because it names them
directly.