Microsoft

Microsoft Releases Emergency Security Fixes For Exchange Server

Microsoft has started an emergency mitigation service that provides security for Exchange servers until there is a permanent solution. The whole thing is a new feature that is now being established in response to persistent security problems.

This is reported by The Record. Microsoft is now adding a new function to Exchange servers that makes it possible to provide temporary emergency corrections at any time. The provision of the so-called Emergency Mitigation Service (EM) started a few days ago. The new security feature for Exchange email servers is being introduced because it has been the focus of several major hacking campaigns over the past two years. The new feature automatically installs temporary remedial measures that block active exploitation of vulnerabilities until Microsoft is ready to release official patches. The administrators will then have to provide these patches as usual.

The cumulative updates from September are required

By default, EM service will be enabled for all Exchange servers once the September 2021 Cumulative Updates (CUs) for Exchange servers are installed. The update is a prerequisite for receiving the EM services. This emergency function should actually be started in mid-September, but the release has been delayed due to new weaknesses.

Under the hood, the service works automatically by establishing a connection to the Office Config Service (OCS) and downloading attenuations (in the form of XML rules) from the following URL: officeclient.microsoft.com/getexchangemitigations

The attenuations include three types of configuration changes:

  • Weakening of the IIS URL rewrite rule. This is a rule that blocks certain patterns of malicious HTTP requests that can compromise an Exchange server.
  • Exchange service degradation. This will disable a vulnerable service on an Exchange server.
  • App Pool Mitigation: Deactivates a vulnerable app pool on an Exchange server.

As soon as Microsoft detects a new attack, the security team will distribute temporary weakenings via EM to all Exchange servers worldwide and start working on a software patch.

Deactivation of the service

“Since remedies can be published at any time in the future, we have decided to let the EM service search for remedies every hour,” explained the Microsoft Exchange team. For Exchange servers installed in highly secure environments, Microsoft also offers a way to disable the EM service so that administrators can apply mitigation measures manually or with the Exchange On-premises Mitigation Tool (EOMT).

Recent Posts

Navigating the Digital Frontier: How Mobile Proxy Infrastructure Empowers Modern Technology Journalism and Enterprise Data Mining

For tech analysts, software engineers, and digital journalists tracking real-time market shifts on platforms like…

3 hours ago

Decoupling Digital Identity: How Modern App Ecosystems Rely on Virtual Telecommunications Architecture

Modern mobile security models treat phone numbers as default digital passports, forcing tech consumers and…

3 hours ago

Top Extended Detection and Response Platforms for Large Enterprises: A Vendor Comparison Guide

Large enterprises have a lot of security data, but identifying the signals that truly matter…

3 hours ago

5 Lab Methods Scientists Use to Find What’s Really in Tap Water

A glass of tap water reveals little about its chemical makeup. Clear water may still…

23 hours ago

Medical Technology Leadership Programs and Industry Collaborators: The Essential Resource Roundup

In today’s healthcare landscape, collaboration between academic programs and corporate leaders fuels both technological innovation…

2 days ago

Smartphone ban: Italy will soon pay for distracted pedestrians

Italy is cracking down on cell phone use in traffic and will soon be targeting…

2 days ago