微软2022年5月安全补丁Exchange有份!

2021年5月11日,微软发布了5月份的安全补丁,其中包括Exchange Server,建议大家关注!

1、漏洞影响:

本次更新主要解决一个特权提升漏洞(CVE-2022-21978),涉及Exchange 2013、2016、2019三个支持期版本,CVSS得分为8.2,微软说虽然目前还有被利用的公开案例,但还是建议尽快更新,以下微软发布的公告:

CVE-2022-21978 Microsoft Exchange Server Elevation of Privilege Vulnerability

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21978

除此以外,据产品组的发布文档,本次SU还解决了下面几个产品问题:


2、针对这次安全更新发布的KB列表如下:

Exchange Server 2013版本:

http://support.microsoft.com/kb/5014260

Exchange Server 2016、2019版本:

http://support.microsoft.com/kb/5014261

3、补丁下载地址如下:

Security Update For Exchange Server 2019 CU12补丁下载地址:

https://www.microsoft.com/en-us/download/details.aspx?id=104205

Security Update For Exchange Server 2019 CU11补丁下载地址:

https://www.microsoft.com/en-us/download/details.aspx?id=104206

Security Update For Exchange Server 2016 CU23补丁下载地址:

https://www.microsoft.com/en-us/download/details.aspx?id=104207

Security Update For Exchange Server 2016 CU22补丁下载地址:

https://www.microsoft.com/en-US/download/details.aspx?id=104208

Security Update For Exchange Server 2013 CU23补丁下载地址:

https://www.microsoft.com/en-us/download/details.aspx?id=104209

4、补丁安装建议

5、提供EXE扩展名补丁文件

自本次SU补丁开始,微软提供EXE扩展名的补丁用于从手动下载的用户,以解决之前MSP格式补丁被直接双击执行的权限问题,现在执行EXE文件会检查权限并提示提权,详细说明请参考下文:

https://techcommunity.microsoft.com/t5/exchange-team-blog/new-exchange-server-security-update-and-hotfix-packaging/ba-p/3301819

6、安装完SU后,还要进行域准备

安装完本次SU后,需要利用Exchange安装目录\bin下的setup.exe手动进行一次AD域准备,以完全修复漏洞,如:

Setup.exe /IAcceptExchangeServerLicenseTerms_DiagnosticDataON /PrepareAllDomains

Setup.exe /IAcceptExchangeServerLicenseTerms /PrepareAllDomains

最后,提醒大家,如果您计划安装新的更新,请认真阅读发布文档,做好评估和测试后在生产环境执行。如果您有问题,欢迎留言或是到5DMail专属微信群来讨论!

分享到