Critical security update for all Exchange Server versions (MS16-108)

Outside the usual patch interval for Exchange Server, Microsoft has released a security update for all Exchange Server versions, which is intended to fix several security vulnerabilities classified as high or critical.

Here is the link to the Security Bulletin:

Microsoft Security Bulletin MS16-108

Brief description of the vulnerability:

This security update resolves vulnerabilities in Microsoft Exchange Server. The most severe vulnerabilities could allow remote code execution in some Oracle Outside In libraries built into Exchange Server if attackers send email with a specially crafted attachment to a vulnerable Exchange server.

Source: Microsoft

Click here to download the update for the respective Exchange versions:

I am currently installing the update, which is taking some time:

Security update

As the vulnerability can apparently be exploited by an email, the update should be installed quickly. Unfortunately, no corresponding warning has yet been published on the Exchange Team Blog.

2 thoughts on “Kritisches Sicherheitsupdate für alle Exchange Server Versionen (MS16-108)”

Leave a Comment