CVE-2025-25006
Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C
- EPSS probability
- 0.85%
- CWE
- CWE-167
- Published
- 2025-08-12
- Last modified
- 2026-03-12
Affected products
- Microsoft Microsoft Exchange Server 2016 Cumulative Update 23
- Microsoft Microsoft Exchange Server 2019 Cumulative Update 14
- Microsoft Microsoft Exchange Server 2019 Cumulative Update 15
- Microsoft Microsoft Exchange Server Subscription Edition RTM
Weakness type
Related vulnerabilities
- CVE-2025-30656 — Junos OS: MX Series, SRX Series: Processing of specific SIP INVITE messages by the SIP ALG will lead to an FPC crash
- CVE-2023-4809 — pf incorrectly handles multiple IPv6 fragment headers
- CVE-2023-3580 — Improper Handling of Additional Special Element in squidex/squidex
- CVE-2023-0643 — Improper Handling of Additional Special Element in squidex/squidex