Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
                
            References
                    | Link | Resource | 
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-25007 | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    03 Sep 2025, 14:51
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_22:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_7:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:-:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_3:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_6:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_8:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_4:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_2:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_9:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_12:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_15:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:*:*:*:*:subscription:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_10:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_6:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_7:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_19:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_13:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_8:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_10:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_21:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_5:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_16:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_17:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_3:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_11:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:-:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_9:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_14:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_4:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_2:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_13:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_18:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_12:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_1:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_1:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_20:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_5:*:*:*:*:*:* cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_11:*:*:*:*:*:* | |
| References | () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-25007 - Vendor Advisory | |
| First Time | Microsoft exchange Server Microsoft | 
13 Aug 2025, 17:34
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
 | 
12 Aug 2025, 18:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-08-12 18:15
Updated : 2025-09-03 14:51
NVD link : CVE-2025-25007
Mitre link : CVE-2025-25007
CVE.ORG link : CVE-2025-25007
JSON object : View
Products Affected
                microsoft
- exchange_server
CWE
                
                    
                        
                        CWE-1286
                        
            Improper Validation of Syntactic Correctness of Input
