With the HAFNIUM experience still fresh in mind, we are a bit worried about other vulnerabilities and security updates for Exchange. The last two weeks there were rumors about new vulnerabilities in Exchange.
On April 13, 2021 Microsoft released new and urgent security updates for Exchange server 2013, 2016 and 2019 that addresses four Remote Code vulnerabilities:
More information regarding the Exchange security update can be found in Microsoft knowledgebase article KB5001779, you can download the Security Updates from the following locations:
Exchange 2019 CU9 - https://www.microsoft.com/en-us/download/details.aspx?id=103004
Exchange 2019 CU8 - https://www.microsoft.com/en-us/download/details.aspx?id=103003
Exchange 2016 CU20 - https://www.microsoft.com/en-us/download/details.aspx?id=103002
Exchange 2016 CU19 - https://www.microsoft.com/en-us/download/details.aspx?id=103001
Exchange 2013 CU23 - https://www.microsoft.com/en-us/download/details.aspx?id=103000
A couple of remarks regarding these security updates:
Do you have numerous Exchange servers that need to be patched? Understanding the version and patch you are currently running enables you to access the security risk in your environment and ensure the patch was successfully installed. The Exchange version report simply returns back the information needed to understand what version your servers are running and if the security patch was successful.
PS -don’t forget to reboot your server after applying the patch).