Microsoft calls on IT admins to take extra steps to shield against Exchange vulnerabilities


Microsoft has addressed a number of Exchange Server flaws in its latest Patch (opens in new tab) Tuesday cumulative security update – however IT admins will also need to enable Extended Protection to fully mitigate some of them.
Extended Protection is a tool that enhances existing Windows Server authentication, and mitigates man-in-the-middle attacks, or authentication relays. The feature does so by using security information implemented through Channel-binding information, specified through a Channel Binding Token, primarily used for SSL connections.
This month’s cumulative update addresses a total of 121 vulnerabilities, including a number of Exchange flaws, such as CVE-2022-21980, CVE-2022-24477, and CVE-2022-24516, which are all rated as critical as they allow for the escalation of privilege. These flaws can even be exploited by low-skilled threat actors, making them particularly dangerous. All of them, however, require the victim to visit a malicious server (opens in new tab).
Exploitation more likely
“Although we are not aware of any active exploits in the wild, our recommendation is to immediately install these updates to protect your environment,” the Exchange Server Team said.
“Customers vulnerable to this issue would need to enable Extended Protection in order to prevent this attack,” the team added. “Please note that enabling Extended Protection (EP) is only supported on specific versions of Exchange (please see documentation for a full list of prerequisites).”
Just because crooks aren’t yet exploiting these flaws, it doesn’t mean they won’t. Microsoft labeled all three flaws as “exploitation more likely”, suggesting IT admins apply the fixes immediately, as it’s only a matter of time before crooks start abusing the holes to deliver malware (opens in new tab).
“Microsoft analysis has shown that exploit code could be created in such a way that an attacker could consistently exploit this vulnerability. Moreover, Microsoft is aware of past instances of this type of vulnerability being exploited,” Microsoft said.
“This would make it an attractive target for attackers, and therefore more likely that exploits could be created. As such, customers who have reviewed the security update and determined its applicability within their environment should treat this with a higher priority.”
Microsoft built a script that enables this feature, but advises admins to carefully evaluate their environments before using it on their servers.
Via: BleepingComputer (opens in new tab)
Audio player loading… Microsoft has addressed a number of Exchange Server flaws in its latest Patch (opens in new tab) Tuesday cumulative security update – however IT admins will also need to enable Extended Protection to fully mitigate some of them. Extended Protection is a tool that enhances existing Windows…
Recent Posts
- No, it’s not an April fool, Intel debuts open source AI offering that gauges a text’s politeness level
- It’s clearly time: all the news about the transparent tech renaissance
- Windows 11 24H2 hasn’t raised the bar for the operating system’s CPU requirements, Microsoft clarifies
- Acer is the first to raise laptop prices because of Trump
- OpenSSH vulnerabilities could pose huge threat to businesses everywhere
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010