What is it? Microsoft is investigating targeted attacks on their on premises Email servers. Attackers have found a way into servers that are already
[See the full post at: Microsoft email zero day]
Susan Bradley Patch Lady/Prudent patcher
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
Home » Forums » Newsletter and Homepage topics » Microsoft email zero day
What is it? Microsoft is investigating targeted attacks on their on premises Email servers. Attackers have found a way into servers that are already
[See the full post at: Microsoft email zero day]
Susan Bradley Patch Lady/Prudent patcher
Is this disturbing that EVERY time there is a zero day in Microsoft on premises email servers, Microsoft can conveniently scramble and get their online servers patched and meanwhile those that purchase on premises software are stuck holding the bag.
Would it be less disturbing if Microsoft didn’t patch their own servers immediately (while asking everyone else to do so)?
Then they can be a bit more proactive and include these mitigations in the tool that they supposedly wrote to help protect for these zero days. Currently it doesn’t help to protect servers for this issue.
Susan Bradley Patch Lady/Prudent patcher
include these mitigations in the tool that they supposedly wrote to help protect for these zero days
Good news. They have as of October first. Those who have installed Exchange Server Emergency Mitigation and enabled it, the fix is applied automatically. Won’t hurt to check if it actually did, see the topic Controlling automatic mitigation in your environment
As you say; it does make you wonder how MS patches it’s own Exchange servers; assuming they run Exchange for their MS 365 solutions.
September 30, 2022 updates:
Added link to Microsoft Security blog in Summary.
Microsoft released the Exchange Server Emergency Mitigation Service (EMS) mitigation for this issue.
Microsoft created a script for the URL Rewrite mitigation steps and modified step 6 in the Mitigations section.
Option 1: For customers who have the Exchange Server Emergency Mitigation Service (EMS) enabled, Microsoft released the URL Rewrite mitigation for Exchange Server 2016 and Exchange Server 2019. The mitigation will be enabled automatically. Please see this blog post for more information on this service and how to check active mitigations.Option 2: Microsoft created the following script for the URL Rewrite mitigation steps. https://aka.ms/EOMTv2
Option 3: Customers can follow the below instructions, which are currently being discussed publicly and are successful in breaking current attack chains.
Customer Guidance for Reported Zero-day Vulnerabilities in Microsoft Exchange Server
Exchange 2010 is not vulnerable.
Susan Bradley Patch Lady/Prudent patcher
Seems poor configuration was part of the problem.. (or is this another “incident”? This is October 4th..)
Should anyone be able to make use of this..
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.