Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
The product uses an authentication mechanism to restrict access to specific users or identities, but the mechanism does not sufficiently prove that the claimed identity is correct.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Exchange_server | Microsoft | * | 15.02.2562.029 (excluding) |
| Exchange_server | Microsoft | 2016 (including) | 2016 (including) |
| Exchange_server | Microsoft | 2016-cumulative_update_1 (including) | 2016-cumulative_update_1 (including) |
| Exchange_server | Microsoft | 2016-cumulative_update_10 (including) | 2016-cumulative_update_10 (including) |
| Exchange_server | Microsoft | 2016-cumulative_update_11 (including) | 2016-cumulative_update_11 (including) |
| Exchange_server | Microsoft | 2016-cumulative_update_12 (including) | 2016-cumulative_update_12 (including) |
| Exchange_server | Microsoft | 2016-cumulative_update_13 (including) | 2016-cumulative_update_13 (including) |
| Exchange_server | Microsoft | 2016-cumulative_update_14 (including) | 2016-cumulative_update_14 (including) |
| Exchange_server | Microsoft | 2016-cumulative_update_15 (including) | 2016-cumulative_update_15 (including) |
| Exchange_server | Microsoft | 2016-cumulative_update_16 (including) | 2016-cumulative_update_16 (including) |
| Exchange_server | Microsoft | 2016-cumulative_update_17 (including) | 2016-cumulative_update_17 (including) |
| Exchange_server | Microsoft | 2016-cumulative_update_18 (including) | 2016-cumulative_update_18 (including) |
| Exchange_server | Microsoft | 2016-cumulative_update_19 (including) | 2016-cumulative_update_19 (including) |
| Exchange_server | Microsoft | 2016-cumulative_update_2 (including) | 2016-cumulative_update_2 (including) |
| Exchange_server | Microsoft | 2016-cumulative_update_20 (including) | 2016-cumulative_update_20 (including) |
| Exchange_server | Microsoft | 2016-cumulative_update_21 (including) | 2016-cumulative_update_21 (including) |
| Exchange_server | Microsoft | 2016-cumulative_update_22 (including) | 2016-cumulative_update_22 (including) |
| Exchange_server | Microsoft | 2016-cumulative_update_3 (including) | 2016-cumulative_update_3 (including) |
| Exchange_server | Microsoft | 2016-cumulative_update_4 (including) | 2016-cumulative_update_4 (including) |
| Exchange_server | Microsoft | 2016-cumulative_update_5 (including) | 2016-cumulative_update_5 (including) |
| Exchange_server | Microsoft | 2016-cumulative_update_6 (including) | 2016-cumulative_update_6 (including) |
| Exchange_server | Microsoft | 2016-cumulative_update_7 (including) | 2016-cumulative_update_7 (including) |
| Exchange_server | Microsoft | 2016-cumulative_update_8 (including) | 2016-cumulative_update_8 (including) |
| Exchange_server | Microsoft | 2016-cumulative_update_9 (including) | 2016-cumulative_update_9 (including) |
| Exchange_server | Microsoft | 2019 (including) | 2019 (including) |
| Exchange_server | Microsoft | 2019-cumulative_update_1 (including) | 2019-cumulative_update_1 (including) |
| Exchange_server | Microsoft | 2019-cumulative_update_10 (including) | 2019-cumulative_update_10 (including) |
| Exchange_server | Microsoft | 2019-cumulative_update_11 (including) | 2019-cumulative_update_11 (including) |
| Exchange_server | Microsoft | 2019-cumulative_update_12 (including) | 2019-cumulative_update_12 (including) |
| Exchange_server | Microsoft | 2019-cumulative_update_13 (including) | 2019-cumulative_update_13 (including) |
| Exchange_server | Microsoft | 2019-cumulative_update_2 (including) | 2019-cumulative_update_2 (including) |
| Exchange_server | Microsoft | 2019-cumulative_update_3 (including) | 2019-cumulative_update_3 (including) |
| Exchange_server | Microsoft | 2019-cumulative_update_4 (including) | 2019-cumulative_update_4 (including) |
| Exchange_server | Microsoft | 2019-cumulative_update_5 (including) | 2019-cumulative_update_5 (including) |
| Exchange_server | Microsoft | 2019-cumulative_update_6 (including) | 2019-cumulative_update_6 (including) |
| Exchange_server | Microsoft | 2019-cumulative_update_7 (including) | 2019-cumulative_update_7 (including) |
| Exchange_server | Microsoft | 2019-cumulative_update_8 (including) | 2019-cumulative_update_8 (including) |
| Exchange_server | Microsoft | 2019-cumulative_update_9 (including) | 2019-cumulative_update_9 (including) |
Attackers may be able to bypass weak authentication faster and/or with less effort than expected.