exchange

Critical Microsoft Exchange Patch - CVE-2018-8154 patch

Microsoft has released a update to address a critical vulnerability for all Exchange versions

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8154

A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the System user. An attacker could then install programs; view, change, or delete data; or create new accounts.

Exploitation of the vulnerability requires that a specially crafted email be sent to a vulnerable Exchange server.

The security update addresses the vulnerability by correcting how Microsoft Exchange handles objects in memory.

Exchange 2007 will not be patched by Microsoft so if you are using this version its highly recommended you update or migrate to Office 365



Careful with Windows Update .NET 4.7 Upgrade

Be careful installing this update on Exchange Servers per Microsoft Recommendations

https://redmondmag.com/articles/2017/06/13/avoid-net-framework-4-7.aspx

There are some also Current Known Issues Listed here

https://support.microsoft.com/en-us/help/4015088/known-issues-in-the-net-framework-4-7

Careful installing this manually or approving this via WSUS!