Please help! what vulnerability that I got and how to fix?

Tanisorn Sowudomsilp 231 Reputation points
2023-01-12T02:17:21.1+00:00

Dear All,

My customer Exchange Server is the Exchange 2019 CU12 May 22SU.

I found these alerts in the Crowdstrike detection regarding attacking via w3wp.exe.

Please see the pictures below. How can I fix this vulnerability or any suggestion?

1

2

3

Thank you very much,

Tanisorn.

Exchange Server
Exchange Server
A family of Microsoft client/server messaging and collaboration software.
1,094 questions
Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,479 questions
Exchange Server Development
Exchange Server Development
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Development: The process of researching, productizing, and refining new or existing technologies.
516 questions
Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,364 questions
Microsoft Exchange
Microsoft Exchange
Microsoft messaging and collaboration software.
395 questions
{count} votes

Accepted answer
  1. Aholic Liang-MSFT 13,741 Reputation points Microsoft Vendor
    2023-01-13T02:17:09.2533333+00:00

    Hi @Tanisorn Sowudomsilp

    It is recommended that you use the Exchange Server Health Checker script to check for specific vulnerabilities in the exchange server to determine which updates are required.

     

    In addition , Microsoft has released the January 2023 Exchange Server security update.

    Although we are not aware of any active exploits in the wild, our recommendation is to immediately install these updates to protect your environment.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment". Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread


2 additional answers

Sort by: Most helpful
  1. Tanisorn Sowudomsilp 231 Reputation points
    2023-02-14T04:43:17.5+00:00

    The problem was resolved by updated Exchange Server security update sir.

    Thank you very much,

    Tanisorn

    0 comments No comments