Exchange 2016 CU20

Tee Nhek 41 Reputation points
2022-03-09T20:47:08.24+00:00

Hi,

We are on Exchange 2016 CU20. Just wonder whether this CU20 is affected by the latest security issue below:

CVE-2022-23277 | Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2022-24463 | Microsoft Exchange Server Spoofing Vulnerability

Thanks,

Tee

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,345 questions
0 comments No comments
{count} votes

Accepted answer
  1. Andy David - MVP 141.5K Reputation points MVP
    2022-03-09T21:19:09.37+00:00

    yes, you need to upgrade immediately to a supported version and then apply the latest security update that was released yesterday

    So upgrade to Cu22:
    https://www.microsoft.com/en-us/download/details.aspx?id=103478

    Following:
    https://learn.microsoft.com/en-us/exchange/plan-and-deploy/install-cumulative-updates?view=exchserver-2019

    then apply the security patch:

    https://techcommunity.microsoft.com/t5/exchange-team-blog/released-march-2022-exchange-server-security-updates/ba-p/3247586

    181605-image.png

    0 comments No comments

2 additional answers

Sort by: Most helpful
  1. Aaron Xue-MSFT 2,581 Reputation points Microsoft Vendor
    2022-03-10T02:42:24.423+00:00

    Hi @Tee Nhek ,

    Agree with andy. According to below document, the security issue has been solved in the latest security update
    181695-5.png

    You need to install the CU22 and the latest security.

    Download Exchange CU22 from here.
    https://www.microsoft.com/download/details.aspx?familyID=a7d608a2-d81b-46af-8753-8c3c2ea1f783

    The latest SU March 8, 2022 (KB5012698)
    Description of the security update for Microsoft Exchange Server 2019 and 2016: March 8, 2022 (KB5012698)


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  2. Tee Nhek 41 Reputation points
    2022-03-10T13:08:28.023+00:00

    Thanks guys. We have about 75 mailboxes; how long do you think the update will take?

    Thanks again,

    Tee