
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-64667 is a User Interface (UI) misrepresentation vulnerability in Microsoft Exchange Server that allows an unauthenticated, network-based attacker to perform spoofing attacks by misrepresenting critical information in the Exchange interface. It was disclosed and patched on December 9, 2025, as part of Microsoft's December 2025 Patch Tuesday security update. Affected products include Microsoft Exchange Server 2016 (Cumulative Update 23, versions before 15.01.2507.063), Exchange Server 2019 (Cumulative Update 14 before 15.02.1544.037, and CU15 before 15.02.1748.042), and Exchange Server Subscription Edition RTM (versions before 15.02.2562.035). The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium) (Microsoft MSRC, Feedly).
The root cause is classified as CWE-451 (User Interface Misrepresentation of Critical Information), meaning the Exchange Server UI fails to accurately represent critical information to users or administrators, enabling an attacker to craft network-based interactions that cause the interface to display misleading or spoofed content. Exploitation requires no authentication and no user interaction, and operates over the network with low attack complexity. No technical write-ups or public proof-of-concept code detailing the specific mechanism have been published as of the time of this report (Microsoft MSRC, Feedly).
Successful exploitation results in a low integrity impact — an attacker can manipulate what critical information is displayed in the Exchange Server UI, potentially deceiving users or administrators into taking unintended actions based on falsified information. There is no confidentiality or availability impact. The primary risk is enabling social engineering attacks or misleading administrators about the state of the mail server, which could facilitate further compromise if acted upon (Microsoft MSRC, Feedly).
Microsoft released patches for all affected Exchange Server versions as part of the December 2025 Patch Tuesday update. Organizations should apply the following updates:
As a temporary workaround if immediate patching is not possible, consider limiting network access to Exchange Server and increasing user awareness about potential UI-based social engineering. Upgrading to a patched version is the recommended long-term solution (Microsoft MSRC, Feedly).
The vulnerability was covered as part of broader December 2025 Patch Tuesday roundups by multiple security outlets including BleepingComputer, Sophos, Zero Day Initiative, and SANS ISC, though it received limited individual attention given its medium severity and lack of active exploitation. Security community coverage focused primarily on the three zero-days patched in the same update cycle (BleepingComputer, ZDI, Sophos).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."