Security update for Exchange

Glenn Maxwell 12,876 Reputation points
2025-02-23T15:39:15.66+00:00

Hi All,

I am using an Exchange 2016 hybrid environment. My Exchange servers are running on Exchange Server 2016 CU23 Nov24SUv2. We have a third-party vulnerability scanning tool, and it has detected the following vulnerability on my Exchange servers:

Security updates for Microsoft Exchange Server (February 2024).

I assumed that Exchange Server 2016 CU23 Nov24SUv2 would fix this vulnerability. Could you please guide me on how to resolve it?

[PS] C:\windows\system32>Get-Command Exsetup.exe | ForEach {$_.FileVersionInfo}

ProductVersion   FileVersion      FileName
--------------   -----------      --------
15.01.2507.044   15.01.2507.044   C:\Program Files\Microsoft\Exchange Server\V15\bin\ExSetup.exe


[PS] C:\windows\system32>Get-Command Exsetup.exe | fl


Name            : ExSetup.exe
CommandType     : Application
Definition      : C:\Program Files\Microsoft\Exchange Server\V15\bin\ExSetup.exe
Extension       : .exe
Path            : C:\Program Files\Microsoft\Exchange Server\V15\bin\ExSetup.exe
FileVersionInfo : File:             C:\Program Files\Microsoft\Exchange Server\V15\bin\ExSetup.exe
                  InternalName:     ExSetup.exe
                  OriginalFilename: ExSetup.exe
                  FileVersion:      15.01.2507.044
                  FileDescription:
                  Product:          Microsoft® Exchange
                  ProductVersion:   15.01.2507.044
                  Debug:            False
                  Patched:          False
                  PreRelease:       False
                  PrivateBuild:     False
                  SpecialBuild:     False
                  Language:         Language Neutral

Exchange | Hybrid management
0 comments No comments
{count} votes

Accepted answer
  1. Anonymous
    2025-02-24T03:07:01.5666667+00:00

    Hi @Glenn Maxwell ,

    Welcome to the Microsoft Q&A platform!

    Microsoft has released KB5035606 to address this issue or enable Extended Protection for Authentication (EPA) to prevent this vulnerability.

    Since updates have been suspended for the 2016 version, it is recommended to upgrade to 2019 if possible to avoid potential vulnerabilities.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Andy David - MVP 157.8K Reputation points MVP Volunteer Moderator
    2025-02-24T12:53:03.1966667+00:00
    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.