Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.
Is Exchange Online affected, and do Exchange Online customers need to take action? Microsoft has already deployed a related service-side fix to Exchange Online. Exchange Online customers do not need to take any action to receive the fix. Customers using affected on-premises Microsoft Exchange Server products should install the applicable security updates listed in the Security Updates table. Where can I find more information? Please see the Exchange blog for more information. What privileges could be gained by an attacker who successfully exploited this vulnerability? An authenticated attacker who successfully exploited this vulnerability could gain unauthorized access to other users' mailboxes within the same organization and read email messages and attachments. The vulnerability does not allow access across tenant boundaries.
Jan Mitchell from Microsoft