HomeSecurityMicrosoft Exchange: New feature automatically mitigates high-risk bugs

Microsoft Exchange: New feature automatically mitigates high-risk bugs

Microsoft has added a new feature to Exchange Server that automatically applies temporary mitigations for high-risk (and potentially actively exploited) security flaws to protect on-premises servers from incoming attacks and give administrators more time to apply security updates.

This update comes in the wake of multiple Microsoft Exchange zero-day vulnerabilities exploited by state-sponsored hacking groups with financial incentives to compromise servers whose administrators did not have a patch or mitigation in place.

See also: Microsoft Exchange Autodiscover: Bugs leak Windows credentials

Microsoft Exchange

See also: Microsoft: Delete passwords in Windows 10 immediately

Automatic protection for vulnerable Exchange servers

The new Exchange Server component, aptly named Microsoft Exchange Emergency Mitigation (EM) service, builds on Microsoft's Exchange On-Interior Mitigation Tool (EOMT) that was released in March to help customers minimize the "attack surface" exposed by ProxyLogon flaws

EM runs as a Windows service on Exchange Mailbox servers and will be automatically installed on servers with the Mailbox role after deploying the September 2021 CU (or later) on Exchange Server 2016 or Exchange Server 2019.

It works by detecting Exchange Servers vulnerable to one or more known threats and applies temporary mitigations until a security update for administrators to install.

Mitigations that are automatically applied through the EM service are temporary fixes until the Security Update that fixes the vulnerability can be installed and do not replace Exchange SUs.

See also: Microsoft accounts: You can log in without a password

Optional feature that can be disabled

EM is a version of EOMT that is integrated with Exchange Server and works with the cloud-based Office Config Service (OCS) to capture and protect against high-risk errors with known mitigations.

Administrators can disable the EM service if they don't want Microsoft to automatically apply mitigations to Exchange servers.

They can also control applied mitigations using PowerShell, which allow them to view, reapply, block, or remove mitigations.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS