← Intelligence Center

Microsoft Releases Guidance on High-Severity Vulnerability (CVE-2025-53786) in Hybrid Exchange Deployments

PublishedAug 7, 2025
Updated
VendorMicrosoft
SeverityHigh
Known ExploitedNo
Advisory IDINTEL-000020
CVEs
CVE-2025-53786
Products
  • Microsoft Exchange Server (hybrid deployments)

Executive Summary

CISA is aware of the newly disclosed high-severity vulnerability CVE-2025-53786, which allows a cyber threat actor with administrative access to an on-premise Microsoft Exchange server to escalate privileges by exploiting vulnerable hybrid-joined configurations. If not addressed, the vulnerability could impact the identity integrity of an organization's Exchange Online service. Microsoft has stated there is no observed exploitation as of the time of the alert's publication. CISA strongly urges organizations to implement Microsoft's guidance or risk hybrid cloud and on-premises total domain compromise.

Municipal Impact

Municipalities operating Exchange hybrid deployments should review Microsoft's guidance, install hotfixes, and verify service principal configuration to avoid domain compromise.

SMB Impact

SMBs with Exchange hybrid deployments should install the April 2025 Exchange Server hotfix updates and follow the dedicated hybrid app deployment guidance.

Recommended Actions

  1. Review Microsoft's Exchange Server Security Changes for Hybrid Deployments guidance to determine if hybrid deployments are affected.
  2. Install Microsoft's April 2025 Exchange Server Hotfix Updates on on-premise Exchange servers and follow configuration instructions to deploy the dedicated Exchange hybrid app.
  3. Review Microsoft's Service Principal Clean-Up Mode guidance to reset the service principal's keyCredentials.
  4. Run the Microsoft Exchange Health Checker to determine if further remediation is required.

Grey Matter Analysis

Analysis pending review.

References

Tags

MicrosoftExchange ServerCVE-2025-53786Elevation of PrivilegeHybrid DeploymentExchange OnlineHotfix

Related Intelligence

Need help with this advisory?

Contact Grey Matter to assess your exposure and prioritize remediation.

Contact Grey Matter