Microsoft has added a new feature to Exchange Server that automatically applies temporary mitigations for high-risk (and potentially actively exploited) security flaws to protect on-premises servers from incoming attacks and give administrators more time to apply security updates.
This update comes in the wake of multiple Microsoft Exchange zero-day vulnerabilities exploited by state-sponsored hacking groups with financial incentives to compromise servers whose administrators did not have a patch or mitigation in place.
See also: Microsoft Exchange Autodiscover: Bugs leak Windows credentials

See also: Microsoft: Delete passwords in Windows 10 immediately
Automatic protection for vulnerable Exchange servers
The new Exchange Server component, aptly named Microsoft Exchange Emergency Mitigation (EM) service, builds on Microsoft's Exchange On-Interior Mitigation Tool (EOMT) that was released in March to help customers minimize the "attack surface" exposed by ProxyLogon flaws
EM runs as a Windows service on Exchange Mailbox servers and will be automatically installed on servers with the Mailbox role after deploying the September 2021 CU (or later) on Exchange Server 2016 or Exchange Server 2019.
It works by detecting Exchange Servers vulnerable to one or more known threats and applies temporary mitigations until a security update for administrators to install.
Mitigations that are automatically applied through the EM service are temporary fixes until the Security Update that fixes the vulnerability can be installed and do not replace Exchange SUs.
See also: Microsoft accounts: You can log in without a password
Optional feature that can be disabled
EM is a version of EOMT that is integrated with Exchange Server and works with the cloud-based Office Config Service (OCS) to capture and protect against high-risk errors with known mitigations.
Administrators can disable the EM service if they don't want Microsoft to automatically apply mitigations to Exchange servers.
They can also control applied mitigations using PowerShell, which allow them to view, reapply, block, or remove mitigations.
Information source: bleepingcomputer.com
