ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Substantial OnPremise Exchange Vulnerabilities announced yesterday Patch Immediately

    IT Discussion
    microsoft exchange on-premise vulnerability critical update
    3
    5
    695
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DustinB3403D
      DustinB3403
      last edited by

      AA21-062A: Mitigate Microsoft Exchange Server Vulnerabilities

      https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26855
      https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26857
      https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26858
      https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-27065

      dbeatoD 1 Reply Last reply Reply Quote 2
      • DustinB3403D
        DustinB3403
        last edited by

        The below powershell should pull logs from your Exchange server to see if you've been compromised.

        Import-Csv -Path (Get-ChildItem -Recurse -Path "$env:PROGRAMFILES\Microsoft\Exchange Server\V15\Logging\HttpProxy" -Filter '*.log').FullName | Where-Object {  $_.AuthenticatedUser -eq '' -and $_.AnchorMailbox -like 'ServerInfo~*/*' } | select DateTime, AnchorMailbox
        
        1 Reply Last reply Reply Quote 0
        • IRJI
          IRJ
          last edited by

          That looks like it's only applicable if you're not using trusted certificates. There's always a man in the middle risk this way.

          1 Reply Last reply Reply Quote 0
          • dbeatoD
            dbeato @DustinB3403
            last edited by

            @DustinB3403 Yeah, Exchange 2013 and over. You have to also be on the last 2 Cumulative Updates from Exchange 2013, 2016 or 2019. For 2019 You only can get the updates through Microsoft Volume Licensing.

            DustinB3403D 1 Reply Last reply Reply Quote 0
            • DustinB3403D
              DustinB3403 @dbeato
              last edited by

              @dbeato said in Substantial OnPremise Exchange Vulnerabilities announced yesterday Patch Immediately:

              @DustinB3403 Yeah, Exchange 2013 and over. You have to also be on the last 2 Cumulative Updates from Exchange 2013, 2016 or 2019. For 2019 You only can get the updates through Microsoft Volume Licensing.

              Yeah, a customer attempted an update from 2016 CU15.1 to CU19, it errored out on the last step, they restored (bad move) and had some mail flow issues for a bit.

              But they are back online now

              1 Reply Last reply Reply Quote 0
              • 1 / 1
              • First post
                Last post