This week Microsoft released new security updates for the following Exchange versions:
Exchange server 2013 CU23
Exchange server 2016 CU22 and CU23
Exchange server 2019 CU11 and CU12
The security updates are cumulative, so they include all updates that are included in previous security updates for a specific cumulative update. These updates also include fixes for zero-days exploits that were reported last month (and unfortunately not included in last month's security update) and discussed in Michel de Rooij’s blog October Exchange Zero Day - Everything You Need to Know and Do on this site.
You can find the downloads on the following locations:
If you are not running the latest (or one previous) CU, please update to the latest CU and install these security updates as there are active exploits on the Internet.
If you have configured the mitigations for last month's exploits, you don’t have to undo those before installing these security updates. If you want to remove the mitigations, do this after you have installed the November 2022 security updates!
Although these are important security updates, please test in your test environment first before installing in your production environment. But because of the active exploits, don’t wait too long before installing in production
Want to learn more about Exchange Monitoring & Reporting?
How do you ensure vital business communication, such as email, stays up and running? How do you demonstrate to senior management that additional resources are needed to meet growing demand or that service levels are being met? ENow makes your job easier by putting everything you need into a single, concise OneLook dashboard, instead of forcing you to use fragmented and complicated tools for monitoring and reporting.
Easy to deploy and intuitive to use, ACCESS YOUR FREE 14-DAY TRIAL and combine all key elements for your Exchange monitoring and reporting to keep your messaging infrastructure up and running like a pro!
Consolidated dashboard view of messaging environments health
Automatically verify external Mail flow, OWA, ActiveSync, Outlook Anywhere
Mail flow queue monitoring
DAG configuration and failover monitoring
Microsoft Security Patch verification
200+ built-in, customizable reports, including: Mailbox size, Mail Traffic, Quota, Storage, Distribution Lists, Public Folders, Database size, OWA, Outlook version, permissions, SLA and mobile device reports
Jaap is a Microsoft MVP for Office Apps and Services. Jaap is an independent consultant, primarily focusing on Exchange server, Skype for Business and Office 365.