Exchange Security Updates – May 2022

/

Once again, we have some important Exchange Security Updates, released with the May 2022 Microsoft Updates.

The latest Exchange Security Updates address vulnerabilities found in the following Exchange Servers:

  • Exchange 2013
  • Exchange 2016
  • Exchange 2019

For more about the vulnerabilities, see the CVEs:

The Security Update is available for the specific Cumulative Update level (CU) your Exchange is running, if you are not up-to-date, with the latest CU, you might have to update the CU before applying the Security Update.

The update path is the following:

thumbnail image 1 of blog post titled 
	
	
	 
	
	
	
				
		
			
				
						
							Released: May 2022 Exchange Server Security Updates

If you are uncertain, about what Exchange Server updates are needed and what current build, your Exchange Servers are running, you can use the Exchange Server Health Checker script to inventory your servers.

If you only have an Exchange Hybrid running, you will still need to update your Exchange environment. You do not need to re-run the Hybrid Configuration Wizard (HCW) after applying updates.

Be aware that a manual run is required to Prepare Add Domains (Schema Update), due to additional security hardening work for CVE-2022-21978.

Read the full process on this, on the Exchange Team blog:

Use the Exchange Update Wizard, if any doubt about the upgrade process:

If you manually install the May 2022 Exchange Security Updates, they can be downloaded here:

  • Exchange Server 2013 CU23
  • Exchange Server 2016 CU22 (Note: CU22 SU update link has been temporarily redirected to the Microsoft Update Catalog .cab download. Please right-click on it, and choose Open and extract the .msp update file and then install it from the elevated command prompt)
  • Exchange Server 2016 CU23
  • Exchange Server 2019 CU11 and CU12

Download the Security Update that is specific to the CU, your Exchange Server is running.

Remember if you install them manually, the install (.msp file) needs to be run from an elevated command prompt.

More details from the original Exchange Team blog post:

It is recommended to update your Exchange Servers as soon as possible.

/Happy Patching! 🙂