Cumulative Update 22 for Exchange 2013 is now available. It contains 3 new documented security updates and 1 additional documented new fix or improvement, as well as all previously released fixes and security updates for Exchange 2013 and the latest DST updates. Note that mainstream support for Exchange 2013 has ended in April 2018.
- ADV190004: February 2019 Oracle Outside In Library Security Update
Microsoft Exchange Server contains some elements of the Oracle Outside In libraries. This update contain fixes to vulnerabilities which are described in: Oracle Critical Patch Update Advisory – October 2018.
- CVE-2019-0686 and CVE-2019-0724: Microsoft Exchange Server Elevation of Privilege Vulnerability
An elevation of privilege vulnerability exists in Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could gain the same rights as a Domain Administrator or gain the same rights as any other user of the Exchange server. This could allow the attacker to perform activities such as accessing the mailboxes of other users. Exploitation of this vulnerability requires Exchange Web Services (EWS) and Push Notifications to be enabled and in use in an affected environment.
To mitigate this vulnerability, AD permissions granted to Exchange server have been modified as discussed in KB4490059: Reducing permissions required to run Exchange Server by using Shared Permissions Model, and additionally changes have been made to EWS authentication as discussed in KB4490060: Exchange Web Services Push Notifications can be used to gain unauthorized access.
- KB4487603: “The action cannot be completed” error when you select many recipients in the Address Book of Outlook in Exchange Server 2013.
This release includes no new updates to the Active Directory Schema.
Download: Cumulative Update 22 for Exchange Server 2013 (KB4345836)
Download: Exchange Server 2013 CU22 UM Language Packs
View: Description of Cumulative Update 22 for Exchange Server 2013
View: Blog post of the Exchange Team about CU22 for Exchange Server 2013