What happen about this? Please suggestion!

Tanisorn Sowudomsilp 251 Reputation points
2023-02-22T04:02:07.12+00:00

Dear All,

Last Friday, I have updated latest SU as the security update for Microsoft Exchange Server 2019, 2016, and 2013: February 14, 2023 (KB5023038) for all Exchange Servers but today I still get the Exchange Server Vulnerability "CVE-2021-34473" and "CVE-2021-31206" notification from Trend Micro product please see the picture below, latest SU no fix these CVEs?

User's image

Thank you very much,

Tanisorn.

Exchange | Exchange Server | Other
Exchange | Exchange Server | Development
Exchange | Exchange Server | Management
{count} votes

Accepted answer
  1. Andy David - MVP 157.8K Reputation points MVP Volunteer Moderator
    2023-02-22T14:21:55.53+00:00

    No, you can't install an older patch. I would suggest you follow the advice for that vulnerability if you want to fix:

    https://www.alitajran.com/cve-2021-1730-vulnerability/


2 additional answers

Sort by: Most helpful
  1. Andy David - MVP 157.8K Reputation points MVP Volunteer Moderator
    2023-02-22T12:37:12.56+00:00

    There was a known issue with the initial offered SU, you may want to download it again and reinstall

    https://techcommunity.microsoft.com/t5/exchange-team-blog/released-february-2023-exchange-server-security-updates/ba-p/3741058

    User's image


  2. Andy David - MVP 157.8K Reputation points MVP Volunteer Moderator
    2023-02-22T13:35:52.02+00:00

    CVE-2021-31206 is old though right?

    Run the health checker against your servers instead to verify you are up to date:

    https://microsoft.github.io/CSS-Exchange/Diagnostics/HealthChecker/

    If it says you are good, then you are ok and the Trend Micro stuff is wrong.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.