The Windows maker said an authenticated attacker can exploit this flaw to gain unauthorized access to other users’ mailboxes within the same organization and read email messages and attachments. However, the vulnerability does not allow cross-tenant access.
Microsoft has already deployed a “related service-side fix” to Exchange Online to address the issue. As a result, Exchange Online customers are not required to take any action.
