Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally.
The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.