There are security update available for the following versions: Microsoft Exchange Server 2019 Cumulative Update 14 Microsoft Exchange Server 2019 Cumulative Update 13 To learn more have a look at: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-21410
Microsoft Exchange Server Vulnerability
Can someone help me with the Microsoft Exchange Server Vulnerability CVE-2024-21410, We don manage exchange server 2013, 2016, and 2019 for our customer, I want to know this Vulnerability applies to which vision and if 2019 Cumulative Update 14 (CU14) is required how I can manage for other version exchange servers.
Exchange | Exchange Server | Management
Exchange | Hybrid management
Windows for business | Windows Server | Devices and deployment | Configure application groups
3 answers
Sort by: Most helpful
-
Reza-Ameri 17,341 Reputation points Volunteer Moderator
2024-02-22T20:26:57.13+00:00 -
Yuki Sun-MSFT 41,376 Reputation points Moderator
2024-02-23T06:34:59.99+00:00 Hi @Nandan NK ,
I want to know this Vulnerability applies to which vision and if 2019 Cumulative Update 14 (CU14) is required how I can manage for other version exchange servers.
This Vulnerability applies to all the Exchange versions you mentioned. According to this blog, enabling EP (Extended Protection) addresses this CVE:
So basically, you can read through the Prerequisites for enabling Extended Protection on Exchange Server then enable EP on the servers when all the prerequisites are met. (You can run the HeathChecker script to check whether your environment has got ready for EP. ) But as is always recommended, it's suggested to update all Exchange versions to the latest CU and install all the SUs.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread. -
Thameur-BOURBITA 36,261 Reputation points Moderator
2024-02-23T09:01:03.3333333+00:00 Hi, Exchange 2013 is no longer supported by Microsoft. Regarding Exchange 2016 and Exchange 2019 you should install the last Cumulitaive Update. For more details please refer to the following link : https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21410
Please don't forget to accept helpful answer