Update Rollup 26 for Exchange 2010 Service Pack 3 is now available. It contains 3 documented new security updates and all previously released fixes and security updates for Exchange 2010 SP3. Note that mainstream support for Exchange 2010 has already ended.
- ADV190004: February 2019 Oracle Outside In Library Security Update
Microsoft Exchange Server contains some elements of the Oracle Outside In libraries. This update contain fixes to vulnerabilities which are described in: Oracle Critical Patch Update Advisory – October 2018.
- CVE-2019-0686 and CVE-2019-0724: Microsoft Exchange Server Elevation of Privilege Vulnerability
An elevation of privilege vulnerability exists in Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could gain the same rights as a Domain Administrator or gain the same rights as any other user of the Exchange server. This could allow the attacker to perform activities such as accessing the mailboxes of other users. Exploitation of this vulnerability requires Exchange Web Services (EWS) and Push Notifications to be enabled and in use in an affected environment.
To mitigate this vulnerability, changes have been made to EWS authentication as discussed in KB4490060: Exchange Web Services Push Notifications can be used to gain unauthorized access. Additionally, you’ll manually have to modify AD permissions granted to Exchange server as discussed in KB4490059: Reducing permissions required to run Exchange Server by using Shared Permissions Model.