External risk intelligence

Pexip Infinity Secure Scheduler Improper Access Control Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2025-59683

Pexip Infinity is a video conferencing and collaboration platform. The Secure Scheduler for Exchange service facilitates integration with external calendar systems, often requiring connectivity to internet-facing services or gateways to function in common enterprise deployment patterns for remote meeting scheduling.

Denial of Service

Pexip Infinity

15 to before 38.1

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Pexip Infinity's Secure Scheduler for Exchange service, affecting versions 15.0 through 38.0. This flaw could allow unauthorized remote access to sensitive data and disrupt service availability by consuming excessive resources. The primary concern is to confirm if our environment is running the affected software.

  • Unauthorized access to sensitive data and service disruption.
  • Potential for data exposure and resource exhaustion.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by targeting the Secure Scheduler for Exchange service, which integrates with external calendar systems. Since no authentication is required and the vulnerability is network-accessible, an attacker can remotely trigger this issue to read sensitive data or cause a denial of service by excessively consuming resources.

  • No authentication required to initiate attack.
  • Vulnerability triggered via external calendar integration.
  • Risk of sensitive data exposure and denial of service.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in Pexip Infinity's Secure Scheduler for Exchange service, when configured with Office 365 Legacy Exchange Tokens, could allow a remote attacker to access sensitive data and cause a denial of service.

  • Sensitive data disclosure and resource exhaustion.
  • Unauthenticated remote access to service.
  • Disruption of service availability.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Pexip Infinity's Secure Scheduler for Exchange service could impact organizations using Office 365 legacy Exchange tokens. The primary teams responsible for addressing this would likely be the platform or infrastructure team managing Pexip Infinity, in coordination with the security team and potentially the vendor management team if Pexip is a managed service. The first practical step is to identify all Pexip Infinity instances, confirm their exposure and criticality, and then determine the accountable owner for remediation planning.

  • Platform/Infrastructure teams own the fix.
  • Verify system reachability and business criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Pexip Infinity used for?

Pexip Infinity is a software platform designed for video conferencing and professional collaboration. Organizations use it to host virtual meetings and integrate communication services, such as connecting their internal video infrastructure with external calendar systems to streamline scheduling for participants.

What does CWE-863 mean for CVE-2025-59683?

CWE-863 refers to Improper Access Control. In the context of this vulnerability, it means the Secure Scheduler service fails to properly verify permissions or identify the requester. Because of this weakness, the system mistakenly grants unauthorized access, allowing remote users to reach data or trigger resource-heavy operations they should be blocked from performing.

How is this vulnerability triggered?

An attacker triggers this by interacting with the Secure Scheduler for Exchange service specifically when it is configured to use Office 365 Legacy Exchange Tokens. It is important to note that if your deployment does not use these legacy tokens for Exchange integration, the specific conditions required to exploit this access control flaw are not met.

Is my Pexip Infinity instance at risk?

According to Halo Surface Signal, this software often requires connectivity to internet-facing services to enable remote scheduling features. If your instance is reachable over the network and configured with the affected legacy tokens, it faces a higher likelihood of being accessible to remote attackers compared to systems restricted to purely internal, non-integrated traffic.

How do I start addressing this vulnerability?

The first step is to conduct an inventory to locate all active Pexip Infinity instances across your environment. Once identified, verify whether they are running an affected version between 15.0 and 38.0 and confirm if they utilize Office 365 Legacy Exchange Tokens. After identifying your current status, coordinate with your infrastructure team to plan the necessary updates to version 38.1 or later.

References