TT-CSIRT – 446.07.08.25 – Privilege Escalation Vulnerability in Microsoft Exchange Hybrid Deployments

TT-CSIRT – 446.07.08.25 – Privilege Escalation Vulnerability in Microsoft Exchange Hybrid Deployments

Please be advised of a high-severity vulnerability, CVE-2025-53786, affecting Microsoft Exchange hybrid deployments. This vulnerability allows a threat actor with administrative access to an on-premise Exchange server to escalate privileges by exploiting vulnerable hybrid-joined configurations.

No active exploitation observed, but CISA urges organizations to implement Microsoft’s Exchange Server Hybrid Deployment Elevation of Privilege Vulnerability guidance to protect Exchange Online identity integrity.

Impact

  • A malicious actor with admin access to an on-premise Exchange server could escalate privileges via misconfigured hybrid-joined environments.
  • May result in full domain compromise, impacting both cloud and on-premise infrastructure.
  • Exploitation risks compromising Exchange Online identity integrity and hybrid trust relationships.

Recommended Mitigation Steps:

  1. Assess Deployment Exposure
    Review Microsoft’s Exchange Server Security Changes for Hybrid Deployments to determine if your hybrid Exchange environment is affected.
  2. Apply April 2025 Hotfixes
    Install Microsoft’s April 2025 Exchange Server Hotfix Updates on all on-premise Exchange servers.
  1. Clean Up Service Principals (If Hybrid Was Previously Used)
    Follow Microsoft’s Service Principal Clean-Up Mode to reset keyCredentials if hybrid Exchange was previously configured but is no longer in use.
  2. Run Exchange Health Checker
    Use the Microsoft Exchange Health Checker to confirm correct configuration and identify any additional required actions.
  3. Disconnect Legacy Systems
    Remove public-facing Exchange or SharePoint servers that have reached end-of-life (EOL) status (e.g., SharePoint Server 2013 or earlier).

References:

If you have any queries, comments, or require assistance, please feel free to contact TT-CSIRT via contacts@ttcsirt.gov.tt.