Microsoft Exchange Server Vulnerability

Nandan NK 50 Reputation points
2024-02-22T17:17:30.2433333+00:00

Can someone help me with the Microsoft Exchange Server Vulnerability CVE-2024-21410, We don manage exchange server 2013, 2016, and 2019 for our customer, I want to know this Vulnerability applies to which vision and if 2019 Cumulative Update 14 (CU14) is required how I can manage for other version exchange servers.

Exchange | Exchange Server | Management
Exchange | Hybrid management
Windows for business | Windows Server | Devices and deployment | Configure application groups
{count} votes

3 answers

Sort by: Most helpful
  1. Reza-Ameri 17,341 Reputation points Volunteer Moderator
    2024-02-22T20:26:57.13+00:00

    There are security update available for the following versions: Microsoft Exchange Server 2019 Cumulative Update 14 Microsoft Exchange Server 2019 Cumulative Update 13 To learn more have a look at: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-21410

    0 comments No comments

  2. Yuki Sun-MSFT 41,376 Reputation points Moderator
    2024-02-23T06:34:59.99+00:00

    Hi @Nandan NK ,

    I want to know this Vulnerability applies to which vision and if 2019 Cumulative Update 14 (CU14) is required how I can manage for other version exchange servers.

    This Vulnerability applies to all the Exchange versions you mentioned. According to this blog, enabling EP (Extended Protection) addresses this CVE:
    User's image

    So basically, you can read through the Prerequisites for enabling Extended Protection on Exchange Server then enable EP on the servers when all the prerequisites are met. (You can run the HeathChecker script to check whether your environment has got ready for EP. ) But as is always recommended, it's suggested to update all Exchange versions to the latest CU and install all the SUs.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  3. Thameur-BOURBITA 36,261 Reputation points Moderator
    2024-02-23T09:01:03.3333333+00:00

    Hi, Exchange 2013 is no longer supported by Microsoft. Regarding Exchange 2016 and Exchange 2019 you should install the last Cumulitaive Update. For more details please refer to the following link : https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21410

    Please don't forget to accept helpful answer

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.