Microsoft pulls Exchange security updates over mail delivery issues
ID: c02a1d79-f168-5844-ae9c-11ac700892fa
STIX ID: report--c02a1d79-f168-5844-ae9c-11ac700892fa
Feed Name: Bleeping Computer
Microsoft pulled the November 2024 Exchange Server security updates after administrators reported that transport (mail flow) and DLP rules stopped processing, causing email delivery outages for Exchange Server 2016 and 2019 systems using those rules. The report also details a high-severity Exchange vulnerability (CVE-2024-49040) that can let attackers forge P2 FROM headers to make spoofed emails appear legitimate; Microsoft added warning behavior via the monthly SU and fixed other zero-days, while advising affected customers to uninstall the buggy SU until a permanent fix is released.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
