Post

Security Update for Exchange Server 2013–2019: Pwn2Own Vulnerabilities

Microsoft released critical security updates for on-premises Exchange Server 2013, 2016, and 2019 to address several remote code execution vulnerabilities.

Security Update for Exchange Server 2013–2019: Pwn2Own Vulnerabilities

Microsoft released critical security updates in April 2021 for on-premises Exchange Server 2013, Exchange Server 2016, and Exchange Server 2019.

The updates address the following remote code execution vulnerabilities:

For additional information, see the following resources:

Important: The Microsoft security updates released in March 2021 do not remediate these vulnerabilities. You can read more about the earlier updates in Exchange Servers: Zero-Day Exploits and Hafnium.

Affected Exchange Versions

The following on-premises Exchange Server versions are affected:

  • Exchange Server 2013.
  • Exchange Server 2016.
  • Exchange Server 2019.

Required Cumulative Updates

The security updates are available for the following Exchange Server cumulative updates:

Exchange Server version Supported cumulative updates
Exchange Server 2013 CU23
Exchange Server 2016 CU19 and CU20
Exchange Server 2019 CU8 and CU9

Cumulative Update Requirements

These security updates are specific to the installed cumulative update level.

For example, you cannot install the security update for Exchange Server 2016 CU20 on a server running Exchange Server 2016 CU19. Before downloading an update, verify the installed Exchange Server version and cumulative update.

The security update download can have the same filename for different cumulative update levels. To avoid confusion, rename the downloaded file to include the applicable cumulative update. For example:

1
Exchange2019-CU9-KB5001779-x64-en.msp

Using the cumulative update level in the filename makes it easier to identify the correct package before installation.

Install the Security Update

Important: If you install the security update manually, you must run the .msp installer from an elevated Command Prompt.

Open Command Prompt as an administrator, change to the directory containing the update, and run the .msp file:

msiexec.exe /update Exchange2019-CU9-KB5001779-x64-en.msp

Replace the filename in the example with the security update that matches your Exchange Server version and cumulative update level.

Before installing the update:

  • Confirm the installed Exchange Server version.
  • Confirm the cumulative update level.
  • Download the matching security update.
  • Verify that the update applies to the intended server.
  • Schedule the installation according to your maintenance procedures.
  • Test the update in a non-production environment where possible.

After installation, verify that the update completed successfully and confirm that the Exchange services and mail flow are operating normally.

This post is licensed under CC BY 4.0 by the author.