Skip to main content

Improper Handling of Additional Special Element

CVE-2025-25006

Severity Medium
Score 5.3/10

Summary

Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

  • LOW
  • NETWORK
  • LOW
  • UNCHANGED
  • NONE
  • NONE
  • NONE
  • NONE

CWE-167 - Improper Handling of Additional Special Element

The software receives input from an upstream component, but it does not handle or incorrectly handles when an additional unexpected special element is provided.

References

Advisory Timeline

  • Published