Trusted by more than 2500 companies with over 5 million users

Microsoft Exchange Server 2013 Nears End of Support

Exchange Server 2013 will reach its end of support on April 11, 2023. If you haven't already begun your migration from Exchange 2013 to Microsoft 365, Office 365, or Exchange 2019, now's the time to start planning. This means all security updates and patches will be ending soon!  After April 11th Microsoft will no longer [...]

Microsoft January 2023 Patch Tuesday: Exchange Server Security Updates

Microsoft has released Security Updates (SUs) for vulnerabilities found in: Exchange Server 2013 Exchange Server 2016 Exchange Server 2019 The updates address the following vulnerabilities: CVE-2023-21745: Spoofing Vulnerability CVE-2023-21761: Information Disclosure Vulnerability CVE-2023-21762: Spoofing Vulnerability CVE-2023-21763: Elevation of Privilege Vulnerability CVE-2023-21764: Elevation of Privilege Vulnerability Official announcement can be found here. SUs are available for [...]

Ransomware Group Targets Microsoft Exchange Server with New Exploit OWASSRF

Threat actors affiliated with the Play ransomware strain are leveraging a never-before-seen exploit method that bypasses Microsoft’s ProxyNotShell URL rewrite mitigation. A New Exploit Chain CrowdStrike researchers have discovered a new exploit method they have named OWASSRF, or Outlook Web Access Server-Side Request Forgery. The novel exploit affects Exchange Server 2013, 2016 and 2019 by leveraging CVE-2022-41080 [...]

Microsoft Exchange ProxyNotShell Vulnerability Explained and How to Mitigate It

ProxyShell and ProxyLogon are two high severity exploits against Microsoft Exchange Servers discovered in 2021. Both vulnerabilities enable threat actors to perform remote code execution on vulnerable systems. A year later, another easily exploitable vulnerability named ProxyNotShell is threatening unpatched Exchange Servers. Here's a great article we recommend you read: Microsoft Exchange ProxyNotShell vulnerability explained [...]

ProxyNotShell Proof-of-Concept Published Online

Security researchers confirm Proof-of-Concept (PoC) works against unpatched versions of Microsoft Exchange Server 2013, 2016 and 2019 In early August, researchers discovered cyberattacks against critical infrastructure using two unpublished Exchange Server security vulnerabilities. Microsoft’s Security Research Center (MSRC) stated: “The first exploit identified as CVE-2022-41040, is a Server-Side Request Forgery (SSRF) vulnerability, and the second one, identified as CVE-2022-41082, allows [...]

Microsoft Exchange – Messageware Q4 2022 Newsletter

The last few months have been busy. Lets look at the happenings and news from the Exchange Server Community: MEC Technical Airlift We hope you attended the Microsoft Exchange Conference ( MEC Technical Airlift ) and had an opportunity to engage with the community and listen to the keynote with Rajesh, Perry, and Jared. In [...]

2022-11-21T10:18:35-05:00News|

Microsoft November 2022 Patch Tuesday: Exchange Server Security Updates

Microsoft has released security updates for two zero-day vulnerabilities: CVE-2022-41040, a server-side request forgery vulnerability, and CVE-2022-41082, which allows remote code execution. Collectively known as ProxyNotShell, the Exchange Server vulnerabilities have led to a spate of attacks linked to nation-state threat actors since late September. The SUs address vulnerabilities responsibly reported to Microsoft by security [...]

On-Premise Chosen over Microsoft 365 due to Server Privacy Concerns

In an ongoing battle that started in 2018 with the EU, several state courts, including the federal German court, found that Microsoft 365 was not compliant with GDPR laws. The ban mostly affects educational institutions and companies that use Microsoft’s 365 product line. The ban comes after Microsoft ended its special arrangements with German users. An [...]

Microsoft October 2022 Patch Tuesday: Exchange Server Security Updates

The SUs address vulnerabilities responsibly reported to Microsoft by security partners and found through Microsoft’s internal processes. Our recommendation is to immediately install these updates to protect your environment. NOTE   The October 2022 SUs do not contain fixes for the zero-day vulnerabilities reported publicly on September 29, 2022 (CVE-2022-41040 and CVE-2022-41082). Please see this blog post to apply mitigations for those [...]

Alert: New Zero-Day Vulnerability Targets Microsoft On-Premise and Hybrid Cloud Exchange Servers

Summary: In early August, researchers from the cybersecurity vendor GTSC discovered cyberattacks against critical infrastructure using two unpublished Exchange Server security vulnerabilities. Microsoft’s Security Research Center (MSRC) stated: “The first exploit identified as CVE-2022-41040, is a Server-Side Request Forgery (SSRF) vulnerability, and the second one, identified as CVE-2022-41082, allows Remote Code Execution (RCE) when PowerShell [...]

Exchange Online Servers Hacked Using Malicious OAuth Applications

Microsoft’s 365 Defender Research Team recently investigated an attack in which malicious OAuth applications were deployed on compromised cloud tenants. Initial Access The attacker first needed to compromise a cloud user’s account that had sufficient permissions in order to create a malicious OAuth application. The threat actor did this by launching credential-stuffing attacks against high-risk [...]

CISA Publishes Mitigation Techniques Against Exchange Server Attacks

In response to the recent targeting of critical infrastructure in the US and abroad, the Cybersecurity and Infrastructure Security Agency (CISA) urges network and security administrators to prepare and immediately mitigate potential cyber threats with the following measures. Implement and apply backup and recovery policies and procedures: Maintain offline backups of data Regularly test backup and restoration Ensure [...]

Nemesis Kitten targets Exchange Server for Attacks

Microsoft Security Threat Intelligence has been tracking multiple ransomware campaigns by a group known as DEV-0270 who also goes by the alias Nemesis Kitten. Who is DEV-0270? DEV-0270, a sub-group of the Iranian threat actor known as PHOSPHORUS, are known for leveraging newly disclosed vulnerabilities against their targets. If successful, the group contacts the victim [...]

Microsoft Exchange Server Security: The 10 Best Ways to Secure Your Server

Security breaches cause organizational chaos, financial and reputation risk. Given how organizations have shifted to a hybrid of in-office and work-from-home, there is a significant increase in the security threat landscape, and it’s more important than ever to improve and harden Exchange Server security. These best practices help provide a baseline security framework that all [...]

Microsoft Exchange – Messageware Q3 2022 Newsletter

Exciting news, MEC (The Microsoft Exchange Conference) is back! The biggest Exchange gathering of the year will be taking place ‘virtually’ Sept 13-14, 2022. It’s been 8 years since the last MEC and we’re excited for candid Q&A and hearing more from Microsoft on the future of Exchange Server. Here’s a link to the registration - https://aka.ms/MECAirlift! Released: [...]

2022-08-24T10:47:09-04:00News|

Microsoft August 2022 Patch Tuesday: Exchange Server vulnerabilities fixed

Microsoft has released security updates (SUs) for vulnerabilities found in: Exchange Server 2013Exchange Server 2016Exchange Server 2019 The SUs address vulnerabilities responsibly reported to Microsoft by security partners and found through Microsoft’s internal processes. Although we are not aware of any active exploits in the wild, our recommendation is to immediately install these updates to protect your [...]

Customer Stories – A Missouri Police Department

When Messageware was approached by a Missouri police department to assist with administrative streamlining, Messageware had the ideal solution. Issues at Hand The department’s administrative staff had been complaining of no MailTo ability for attachments since moving to Office 365. Staff had to re-login to the Outlook web session before they could navigate to attach [...]

Customer Stories – Australian Apparel Retail Chain

When an Australian family-owned apparel retailer found Office 365 hindering their 500+ employees they turned to Messageware. The issue at hand: A customer since 2016, their business uses over one hundred Office 365 K1 Kiosk accounts for their retail stores. As none of these kiosks have mail clients installed on their local computers, they were [...]

Collision Repair Centre uses ActiveSend to Accelerate Assessment Process with Outlook Web

When a chain of collision repair centers in the northeast USA discovered that Outlook web was hindering their unmatchable turnaround times, they approached Messageware. The issue at hand: Staff capture repair estimates for submission to insurers using kiosks conveniently located beside damaged vehicles. However, submitting a vehicle collision report becomes frustrating and time-consuming because Outlook [...]

IceApple exploit framework targeting Microsoft Exchange servers

Stealthy, “highly sophisticated” post-exploitation framework used for data exfiltration likely the work of a state-sponsored threat actor. In late 2021, security researchers on CrowdStrike’s Falcon OverWatch team first detected a modular exploit targeting Microsoft Exchange Servers. Dubbed IceApple, the .NET-based framework has been observed in “distinct locations” and primarily directed toward entities in government, academic [...]

Microsoft Exchange Server Build Numbers, Cumulative Updates (CU), Security Updates (SU) and Release Dates

You can use the information in this article to verify the version of Exchange that is running in your organization. This article is organized in sections that correspond to the major releases of Exchange. Each section lists build numbers for each Service Pack (SP), Cumulative Update (CU), Security Update (SU), or Update Rollup (RU) of [...]

2023-01-19T11:27:35-05:00Microsoft Exchange|

Microsoft Exchange – Messageware Q2 2022 Newsletter

In 2022, a wave of cyberattacks and data breaches swept across the globe after multiple zero-day exploits were discovered in on-premises Microsoft Exchange Servers, giving attackers full access to servers and email. Recently, businesses were warned that Chinese and Russian cyberattacks are imminent and that business leaders must act to strengthen their digital defences. Here [...]

2022-06-11T10:15:53-04:00News|

Microsoft Exchange Server – Cumulative Updates – April 2022

On April 20, 2022 Microsoft released new Cumulative Updates: Exchange 2016 CU23 and Exchange 2019 CU12. The previous Cumulative Updates were released on September 28, 2021, more than 6 months ago.

Microsoft March 2022 Patch Tuesday: 2 Exchange Server vulnerabilities fixed

The March 2022 SUs for Exchange Server address vulnerabilities responsibly reported by security partners and found through Microsoft’s internal processes. Although we are not aware of any active exploits in the wild, our recommendation is to install these updates immediately. These vulnerabilities affect on-premises Exchange Server, including servers used by customers in Exchange Hybrid mode. Exchange [...]

Microsoft launches quarterly Cyber Security Intelligence Brief

Microsoft has just launched a quarterly cyber threat intelligence brief branded Cyber Signals. The new publication offers an expert perspective into the current threat landscape, discussing trending tactics, techniques, and strategies used by the world’s most prolific threat actors.  Cyber Signals is aimed at Chief Information Security Officers, Chief Information Officers, Chief Privacy Officers, and their teams, as they continue [...]

Microsoft revisits the Priority Account Protection in 365

Microsoft revisits the Priority Account Protection in 365:  (Microsoft 365 Defender): Applying a higher level of protection to accounts likely to be targeted by attackers is a more compelling offer as the last thing you want is for an executive to fall foul of a business email compromise attack or other phishing attempts like the recent Office VoIP voicemail [...]

2022-06-14T06:54:33-04:00News|

Microsoft Exchange Server – January 2022 Exchange Server Security Updates

January 2022 Exchange Server Security Updates Microsoft has released security updates for vulnerabilities found in: Exchange Server 2019 Cumulative Update 11 Security Update 3 (KB5008631) Exchange Server 2019 Cumulative Update 10 Security Update 4 (KB5008631) Exchange Server 2016 Cumulative Update 22 Security Update 3 (KB5008631) Exchange Server 2016 Cumulative Update 21 Security Update 4 (KB5008631) Exchange [...]

Microsoft Exchange – Messageware Q4 2021 Newsletter

It's December, and there is plenty of good news... Microsoft has not released any December Exchange Server CUs or SUs, Messageware Exchange Server Guard now secures more Exchange Servers than ever, and the holiday season is upon us! But while everything feels a little more upbeat this week, the second half of 2021 was undoubtedly challenging, with [...]

2022-01-18T10:11:25-05:00News|

Microsoft Exchange Server Security – December 2021 CUs Postponed, Critical SUs Needed

Microsoft announces there is no major CU release for December 2021. Microsoft typically releases Cumulative Updates quarterly for Exchange Server 2019, 2016, and 2013. There have been a number of critical Security Updates since the latest September 2021 CUs: see KB5007409, KB5007012. For convenience, here are direct links to the Microsoft downloads for the latest [...]