CVE-2025-59249

Microsoft Exchange Server Elevation of Privilege Vulnerability

Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.


We have discovered 2,464 live websites that are affected by CVE-2025-59249.

Run a Free Instant Scan




Affected Software

Product  Microsoft Exchange Server
Category Web Mail
Vulnerable Domains2,464 live websites (30% of Microsoft Exchange Server install base)
Vulnerable Versions
  • from 15.1 through 15.1.2507.61
Vulnerable Versions Count25 versions ( 27% of all versions)


Common Weakness Enumeration

CWE-1390 Weak Authentication



Details

  • Published - Oct 14, 2025
  • Updated - Feb 26, 2026

Website Distribution by Country

Number of websites using CVE-2025-59249
United States601 websites



Germany148 websites
Russia138 websites
GB99 websites
France84 websites
Canada80 websites
Czech Republic78 websites
Italy70 websites
Taiwan58 websites
Austria55 websites

Website Distribution by TLD

Number of websites using CVE-2025-59249
.com661 websites
.org204 websites
.ru119 websites
.de116 websites
.net81 websites
.cz71 websites
.fr63 websites
.it51 websites
.edu43 websites
.nl40 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-59249

Top websites that are affected by CVE-2025-59249. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**.de Germany**,***
***.***.tw Taiwan**,***
***************.fr France***,***
*******.***.tw Taiwan***,***
*******.ru Russia***,***
***********.to Tonga***,***
***.***.cl Chile***,***
*******.****.**.za South Africa***,***
*******.**.gov United States***,***
***.***.br Brazil***,***
See full domain list

FAQ

CVE-2025-59249 is Weak Authentication in Microsoft Exchange Server
A total of 2,464 websites have been identified as vulnerable to CVE-2025-59249, based on global website indexing conducted by WebTechSurvey.
The Microsoft Exchange Server is affected by the CVE-2025-59249 vulnerability.
Microsoft Exchange Server versions up to 15.1.2507.61 are vulnerable to CVE-2025-59249.
CVE-2025-59249 is resolved in version 15.1.2507.61 of Microsoft Exchange Server.