Microsoft Exchange Server Spoofing Vulnerability
🔗 CVE IDs covered (1)
📋 Description
Is there additional information I need to know about or actions to perform after installing the update? Yes. Please see the information available in Exchange Server non-RFC compliant P2 FROM header detection.
Why are the Exchange Server updates no longer available on the download center? Microsoft has temporarily paused the rollout of this update. Please see the known issues section of the Exchange Server blog post. We are working on addressing this issue and we'll update this CVE when it is resolved. 11/27/2024 Update: The known issue has been addressed and the update is now re-released.
🎯 Affected products3
- Microsoft Exchange Server 2016 Cumulative Update 23
- Microsoft Exchange Server 2019 Cumulative Update 13
- Microsoft Exchange Server 2019 Cumulative Update 14
✅ Remediation
KB5049233 (Security Update) — fixed build 15.02.1258.039 KB5049233 (Security Update) — fixed build 15.02.1544.014 KB5049233 (Security Update) — fixed build 15.01.2507.044
🔗 References (5)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49040
- patchhttps://www.microsoft.com/download/details.aspx?familyid=56d90b73-4c0a-4cc6-a34e-768284aada1b
- referencehttps://support.microsoft.com/help/5049233
- patchhttps://www.microsoft.com/download/details.aspx?familyid=8b033007-adc3-4ebf-9c3a-f13680c717cb
- patchhttps://www.microsoft.com/download/details.aspx?familyid=e0299b1b-535a-44e0-8f57-ed2b9cc94e6f