ZeroHour
Security Affairspublished ()ingested @securityaffairs

CISA, Microsoft warn of critical Exchange hybrid flaw CVE-2025

criticalExploit / PoC exploited in the wildimportance 60CVE-2025-53786

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-53786
On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix.

On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following further investigation, Microsoft identified specific security implications tied to the guidance and configuration steps outlined in the April announcement. Microsoft is issuing CVE-2025-53786 to document a vulnerability that is addressed by taking the steps documented with the April 18th announcement. Microsoft strongly recommends reading the information, installing the April 2025 (or later) Hot Fix and implementing the changes in your Exchange Server and hybrid environment.

NVD description · AI analysis pending
8.07%
  • microsoft exchange server
  • microsoft exchange server subscription edition
Full article365 words · extracted from securityaffairs.com · click to collapse

CISA and Microsoft warn of CVE-2025-53786, a high-severity Exchange flaw allowing privilege escalation in hybrid cloud environments.

CISA and Microsoft warn of a high-severity flaw, tracked as CVE-2025-53786, in Exchange hybrid deployments that allows attackers to escalate privileges in cloud setups. Microsoft address the vulnerability in Exchange Server 2016, 2019 and Subscription Edition RTM.

The Tech giant highlights that successful exploitation of this vulnerability requires an attacker to first gain or possess administrator access on an Exchange Server.

“In an Exchange hybrid deployment, an attacker who first gains administrative access to an on-premises Exchange server could potentially escalate privileges within the organization’s connected cloud environment without leaving easily detectable and auditable trace.” reads the advisory. “This risk arises because Exchange Server and Exchange Online share the same service principal in hybrid configurations.”

Dirk-jan Mollema, researchers with Outsider Security, reported the vulnerability.

Microsoft is not aware of attacks exploiting this vulnerability in the wild.

“CISA is aware of the newly disclosed high-severity vulnerability, CVE-2025-53786
, that allows a cyber threat actor with administrative access to an on-premise Microsoft Exchange server to escalate privileges by exploiting vulnerable hybrid-joined configurations.” reads the alert published by the US CISA. “This vulnerability, if not addressed, could impact the identity integrity of an organization’s Exchange Online service.”

CISA urges organizations using Microsoft Exchange hybrid deployments to follow Microsoft’s guidance to prevent potential domain compromise, despite no known exploitation of CVE-2025-53786 yet. Key steps include applying the April 2025 hotfix, configuring a dedicated hybrid app, cleaning up service principals if Exchange hybrid is no longer used, and running the Exchange Health Checker. Public-facing EOL versions like SharePoint Server 2013 should be taken offline.

Threat actors frequently exploit Microsoft Exchange Server vulnerabilities. These breaches underscore the persistent risk to Exchange systems and the importance of regular patching and vigilance.

With nearly two dozen vulnerabilities exploited in the wild, it’s clear that Exchange remains a prime targe, even years after patches are issued. Organizations relying on Exchange should stay current with updates and follow CISA and Microsoft security guidance closely to reduce exposure.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Microsoft Exchange)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/180923/security/cisa-microsoft-warn-of-critical-exchange-hybrid-flaw-cve-2025-53786.html