Site icon BW Security World

CISA & Microsoft Warn Of Flaw In Exchange Deployments

2023's Silver Lining: Cybersecurity Moments Of Resilience & Progress In The Industry

2023's Silver Lining: Cybersecurity Moments Of Resilience & Progress In The Industry

The flaw, identified as CVE-2025-53786, affects hybrid setups of Microsoft Exchange Server versions 2016, 2019, and the Subscription Edition

The Cybersecurity and Infrastructure Security Agency (CISA) and Microsoft have issued a joint warning over a new high-severity vulnerability in on-premises Microsoft Exchange servers that could enable an attacker to escalate privileges into cloud-based systems, potentially compromising entire organisational domains.

The flaw, identified as CVE-2025-53786, affects hybrid setups of Microsoft Exchange Server versions 2016, 2019, and the Subscription Edition. If an attacker gains administrative access to an on-premises server, they could exploit the shared authentication mechanism between the on-premises and cloud environments to move laterally and take control of Exchange Online.

CISA stressed that, while no exploitation has been observed in the wild to date, successful attacks could result in a “total domain compromise” — a scenario with serious implications across both cloud and on-premises environments.

In response, CISA has issued an emergency directive requiring all federal agencies using affected hybrid configurations to apply patches, implement recommended mitigations, and report compliance by Monday, 11 August.

Microsoft has released mitigation guidance, including applying the April 2025 hotfixes, configuring a dedicated Exchange hybrid application, cleaning up service principal credentials, and using the Health Checker tool.

The disclosure coincided with a presentation at the Black Hat cybersecurity conference by researcher Dirk-Jan Mollema, who demonstrated the exploit in detail. Microsoft said the timing was coordinated and the vulnerability had been reported weeks earlier.

Exit mobile version