CVE Vulnerabilities

CVE-2025-53782

Incorrect Implementation of Authentication Algorithm

Published: Oct 14, 2025 | Modified: Oct 27, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally.

Weakness

The requirements for the product dictate the use of an established authentication algorithm, but the implementation of the algorithm is incorrect.

Affected Software

NameVendorStart VersionEnd Version
Exchange_serverMicrosoft*15.02.2562.029 (excluding)
Exchange_serverMicrosoft2016 (including)2016 (including)
Exchange_serverMicrosoft2016-cumulative_update_1 (including)2016-cumulative_update_1 (including)
Exchange_serverMicrosoft2016-cumulative_update_10 (including)2016-cumulative_update_10 (including)
Exchange_serverMicrosoft2016-cumulative_update_11 (including)2016-cumulative_update_11 (including)
Exchange_serverMicrosoft2016-cumulative_update_12 (including)2016-cumulative_update_12 (including)
Exchange_serverMicrosoft2016-cumulative_update_13 (including)2016-cumulative_update_13 (including)
Exchange_serverMicrosoft2016-cumulative_update_14 (including)2016-cumulative_update_14 (including)
Exchange_serverMicrosoft2016-cumulative_update_15 (including)2016-cumulative_update_15 (including)
Exchange_serverMicrosoft2016-cumulative_update_16 (including)2016-cumulative_update_16 (including)
Exchange_serverMicrosoft2016-cumulative_update_17 (including)2016-cumulative_update_17 (including)
Exchange_serverMicrosoft2016-cumulative_update_18 (including)2016-cumulative_update_18 (including)
Exchange_serverMicrosoft2016-cumulative_update_19 (including)2016-cumulative_update_19 (including)
Exchange_serverMicrosoft2016-cumulative_update_2 (including)2016-cumulative_update_2 (including)
Exchange_serverMicrosoft2016-cumulative_update_20 (including)2016-cumulative_update_20 (including)
Exchange_serverMicrosoft2016-cumulative_update_21 (including)2016-cumulative_update_21 (including)
Exchange_serverMicrosoft2016-cumulative_update_22 (including)2016-cumulative_update_22 (including)
Exchange_serverMicrosoft2016-cumulative_update_3 (including)2016-cumulative_update_3 (including)
Exchange_serverMicrosoft2016-cumulative_update_4 (including)2016-cumulative_update_4 (including)
Exchange_serverMicrosoft2016-cumulative_update_5 (including)2016-cumulative_update_5 (including)
Exchange_serverMicrosoft2016-cumulative_update_6 (including)2016-cumulative_update_6 (including)
Exchange_serverMicrosoft2016-cumulative_update_7 (including)2016-cumulative_update_7 (including)
Exchange_serverMicrosoft2016-cumulative_update_8 (including)2016-cumulative_update_8 (including)
Exchange_serverMicrosoft2016-cumulative_update_9 (including)2016-cumulative_update_9 (including)
Exchange_serverMicrosoft2019 (including)2019 (including)
Exchange_serverMicrosoft2019-cumulative_update_1 (including)2019-cumulative_update_1 (including)
Exchange_serverMicrosoft2019-cumulative_update_10 (including)2019-cumulative_update_10 (including)
Exchange_serverMicrosoft2019-cumulative_update_11 (including)2019-cumulative_update_11 (including)
Exchange_serverMicrosoft2019-cumulative_update_12 (including)2019-cumulative_update_12 (including)
Exchange_serverMicrosoft2019-cumulative_update_13 (including)2019-cumulative_update_13 (including)
Exchange_serverMicrosoft2019-cumulative_update_2 (including)2019-cumulative_update_2 (including)
Exchange_serverMicrosoft2019-cumulative_update_3 (including)2019-cumulative_update_3 (including)
Exchange_serverMicrosoft2019-cumulative_update_4 (including)2019-cumulative_update_4 (including)
Exchange_serverMicrosoft2019-cumulative_update_5 (including)2019-cumulative_update_5 (including)
Exchange_serverMicrosoft2019-cumulative_update_6 (including)2019-cumulative_update_6 (including)
Exchange_serverMicrosoft2019-cumulative_update_7 (including)2019-cumulative_update_7 (including)
Exchange_serverMicrosoft2019-cumulative_update_8 (including)2019-cumulative_update_8 (including)
Exchange_serverMicrosoft2019-cumulative_update_9 (including)2019-cumulative_update_9 (including)

References