Security Update for Exchange Server 2013–2019: Pwn2Own Vulnerabilities
Microsoft released critical security updates for on-premises Exchange Server 2013, 2016, and 2019 to address several remote code execution vulnerabilities.
Microsoft released critical security updates in April 2021 for on-premises Exchange Server 2013, Exchange Server 2016, and Exchange Server 2019.
The updates address the following remote code execution vulnerabilities:
- CVE-2021-28480: Microsoft Exchange Server Remote Code Execution Vulnerability.
- CVE-2021-28481: Microsoft Exchange Server Remote Code Execution Vulnerability.
- CVE-2021-28482: Microsoft Exchange Server Remote Code Execution Vulnerability.
- CVE-2021-28483: Microsoft Exchange Server Remote Code Execution Vulnerability.
For additional information, see the following resources:
- Microsoft April 2021 Security Update Summary.
- Released: April 2021 Exchange Server Security Updates.
Important: The Microsoft security updates released in March 2021 do not remediate these vulnerabilities. You can read more about the earlier updates in Exchange Servers: Zero-Day Exploits and Hafnium.
Affected Exchange Versions
The following on-premises Exchange Server versions are affected:
- Exchange Server 2013.
- Exchange Server 2016.
- Exchange Server 2019.
Required Cumulative Updates
The security updates are available for the following Exchange Server cumulative updates:
| Exchange Server version | Supported cumulative updates |
|---|---|
| Exchange Server 2013 | CU23 |
| Exchange Server 2016 | CU19 and CU20 |
| Exchange Server 2019 | CU8 and CU9 |
Cumulative Update Requirements
These security updates are specific to the installed cumulative update level.
For example, you cannot install the security update for Exchange Server 2016 CU20 on a server running Exchange Server 2016 CU19. Before downloading an update, verify the installed Exchange Server version and cumulative update.
The security update download can have the same filename for different cumulative update levels. To avoid confusion, rename the downloaded file to include the applicable cumulative update. For example:
1
Exchange2019-CU9-KB5001779-x64-en.msp
Using the cumulative update level in the filename makes it easier to identify the correct package before installation.
Install the Security Update
Important: If you install the security update manually, you must run the
.mspinstaller from an elevated Command Prompt.
Open Command Prompt as an administrator, change to the directory containing the update, and run the .msp file:
msiexec.exe /update Exchange2019-CU9-KB5001779-x64-en.msp
Replace the filename in the example with the security update that matches your Exchange Server version and cumulative update level.
Before installing the update:
- Confirm the installed Exchange Server version.
- Confirm the cumulative update level.
- Download the matching security update.
- Verify that the update applies to the intended server.
- Schedule the installation according to your maintenance procedures.
- Test the update in a non-production environment where possible.
After installation, verify that the update completed successfully and confirm that the Exchange services and mail flow are operating normally.