logo

Microsoft pulls Exchange security updates over mail delivery issues

ID: c02a1d79-f168-5844-ae9c-11ac700892fa

STIX ID: report--c02a1d79-f168-5844-ae9c-11ac700892fa

Feed Name: Bleeping Computer

Threat Score
55/100

Date Published: 2024-11-15

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Microsoft pulled the November 2024 Exchange Server security updates after administrators reported that transport (mail flow) and DLP rules stopped processing, causing email delivery outages for Exchange Server 2016 and 2019 systems using those rules. The report also details a high-severity Exchange vulnerability (CVE-2024-49040) that can let attackers forge P2 FROM headers to make spoofed emails appear legitimate; Microsoft added warning behavior via the monthly SU and fixed other zero-days, while advising affected customers to uninstall the buggy SU until a permanent fix is released.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.