CVE-2025-59683
8.2Pexip · Infinity
Pexip Infinity 15.0 through 38.0 contains an improper access control vulnerability in the Secure Scheduler for Exchange service when using legacy Office 365 tokens.
Executive summary
A critical improper access control vulnerability in Pexip Infinity allows unauthenticated remote attackers to exfiltrate sensitive data and trigger a denial of service.
Vulnerability
The flaw exists within the Secure Scheduler for Exchange service due to incorrect authorization checks (CWE-863). An unauthenticated remote attacker can exploit this to access sensitive information and exhaust system resources, resulting in a denial of service.
Business impact
Successful exploitation poses a significant risk to organizational data confidentiality and service availability. Given the CVSS score of 8.2, the vulnerability is classified as High severity, reflecting the ease of remote exploitation without user interaction or authentication. Compromise could lead to unauthorized information disclosure regarding scheduling and internal communications, while service disruption may impact critical business operations.
Remediation
Immediate Action: Upgrade Pexip Infinity to version 38.1 or later to implement the necessary authorization fixes.
Proactive Monitoring: Review Secure Scheduler for Exchange logs for unusual access patterns or repeated service failures that may indicate exploitation attempts.
Compensating Controls: If patching is delayed, restrict access to the Secure Scheduler service via network-level controls or firewalls to limit exposure to trusted management subnets.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Due to the high CVSS score and the potential for unauthenticated remote impact, this vulnerability represents a significant security risk. IT administrators must prioritize the deployment of the vendor-supplied update to version 38.1. Failure to patch may leave systems vulnerable to information theft and service disruption.