Forum Discussion
Anonymous
7 years agoNot applicable
Tenable published a blog [1] earlier today about a critical...
Tenable published a blog [1] earlier today about a critical privilege escalation bug [2] in fully patched Microsoft Exchange 2013/2016 that would reportedly allow a standard Exchange user to elevate ...
Anonymous
7 years agoNot applicable
Update: Microsoft published[1] a security advisory (ADV190007) that includes a Throttling Policy[2] that will mitigate this vulnerability until a software update. Additionally, they noted that the vulnerability described in the blog post below only affects on-prem deployments of Microsoft Exchange. Microsoft notes in the advisory that this workaround might disrupt some functions in Outlook for Mac, Skype for Business Client, Apple Mail Clients and third-party applications.
[1]https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV190007
[2]https://docs.microsoft.com/en-us/powershell/module/exchange/server-health-and-performance/New-ThrottlingPolicy?view=exchange-ps