Exchange Server Security Updates Available for September 2022 Vulnerabilities

Today’s #MicrosoftCloudQuickFix is that #Microsoft has released the November 2022 Exchange Server Security Updates which contain fixes for the CVE-2022-41040 and CVE-2022-41082 vulnerabilities reported at the end of September 2022 and reported discussed on my blog post below:

Exchange Server Patch Alert! – Microsoft Cloud Quick Fix (mscqf.com)

CVE-2022-41040 is a Server-Side Request Forgery (SSRF) vulnerability and can only be exploited by authenticated attackers while CVE-2022-41082 allows remote code execution (RCE) when PowerShell is accessible to the attacker.

The November 2022 Exchange Server Security Updates are available for Exchange Server 2013 CU23 (Note: Support ends in April 2023), Exchange Server 2016 CU22 and CU23, and Exchange Server 2019 CU11 and CU12. Since #Microsoft has been made aware of active exploits of related vulnerabilities their (and my) recommendation is to install these updates immediately!

Microsoft has indicated that #ExchangeOnline customers are already protected from the vulnerabilities addressed in the November 2022 Exchange Server Security Updates and do not need to take any action other than updating any remaining on-premises Exchange servers.

For more information about this and Exchange Server Patching see:

#Microsoft #Microsoft365 #ExchangeOnline #ExchangeServer #MicrosoftCloudQuickFix

Outlook Cloud Based Signatures

Upgrades to how your email signatures are stored will be launching soon. That is today’s #MicrosoftCloudQuickFix !

Email signatures regardless of your mailbox residing on-premises or in Exchange Online have traditionally been stored on your local computer. Users have had to recreate them every time they reinstall Outlook, move to a new device, or leverage multiple devices.

As outline in Microsoft 365 Roadmap ID 60371 with this change for mailboxes hosted in Exchange Online, #Microsoft will migrate the local signatures to the cloud automatically, no manual steps are required. This means the same set of signatures will be available on any Windows (Microsoft 365) or Web version of Outlook, and you will no longer need to reconfigure your signatures when getting a new device.

Per Microsoft if you use 3rd party solutions in your environment for signature management this change will not impact you at this time.

For more information, please see the following Microsoft Support page.

#MicrosoftCloudQuickFix #Microsoft365 #ExchangeOnline