Microsoft pulls Exchange security updates over mail delivery issues

Share:

Microsoft has pulled the November 2024 Exchange security updates released during this month’s Patch Tuesday because of email delivery issues on servers using custom mail flow rules.

The company announced it pulled the updates from Windows Update and the Download Center following widespread reports from admins saying that email had stopped flowing altogether.

This issue affects customers using transport rules (also known as mail flow rules) or data loss protection (DLP) rules, which will stop periodically after installing the November Exchange Server 2016 and Exchange Server 2019 security updates.

While mail flow rules filter and redirect emails in transit (just as Outlook inbox rules for emails that have already landed in the user’s mailbox), DLP rules prevent sensitive information from being accidentally shared or leaked outside an organization.

“We are continuing the investigation and are working on a permanent fix to address this issue. We will release it when ready. We have also paused the rollout of November 2024 SU to Windows / Microsoft Update,” Redmond said.

Microsoft also advised admins who see mail flow issues to uninstall the buggy November security updates until re-released. However, those who don’t use transport or DLP rules and have not run into this issue can continue using their up-to-date Exchange servers.

Warnings on emails abusing spoofing flaw

This week, Microsoft also disclosed a high-severity Exchange Server vulnerability (CVE-2024-49040) that can let attackers forge legitimate senders on incoming emails to make malicious messages much more effective.

“The vulnerability is caused by the current implementation of the P2 FROM header verification, which happens in transport,” Microsoft explained, warning that the security flaw could be used in spoofing attacks targeting Exchange servers.

“The current implementation allows some non-RFC 5322 compliant P2 FROM headers to pass which can lead to the email client (for example, Microsoft Outlook) displaying a forged sender as if it were legitimate.”

While Microsoft has not patched the vulnerability and will still accept emails with these malformed headers, Redmond says servers will now detect and prepend a warning to malicious emails after installing the Exchange Server November 2024 Security Update (SU).

​Microsoft fixed four zero-days during the November 2024 Patch Tuesday fixes, two actively exploited in attacks and three publicly disclosed.

It also addressed four critical vulnerabilities, including two remote code execution flaws and two elevations of privileges bugs.

Sergiu Gatlan

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
4:11 pm, Jun 30, 2025
weather icon 32°C
L: 31° | H: 34°
clear sky
Humidity: 41 %
Pressure: 1016 mb
Wind: 7 mph SW
Wind Gust: 12 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 1%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:46 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
31° | 34°°C 0 mm 0% 10 mph 43 % 1015 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
20° | 33°°C 0 mm 0% 11 mph 67 % 1016 mb 0 mm/h
Wed Jul 02 10:00 pm
weather icon
18° | 23°°C 0.38 mm 38% 12 mph 80 % 1023 mb 0 mm/h
Thu Jul 03 10:00 pm
weather icon
15° | 26°°C 0 mm 0% 6 mph 76 % 1028 mb 0 mm/h
Fri Jul 04 10:00 pm
weather icon
16° | 28°°C 0 mm 0% 11 mph 55 % 1027 mb 0 mm/h
Today 7:00 pm
weather icon
28° | 31°°C 0 mm 0% 10 mph 39 % 1015 mb 0 mm/h
Today 10:00 pm
weather icon
24° | 27°°C 0 mm 0% 2 mph 43 % 1015 mb 0 mm/h
Tomorrow 1:00 am
weather icon
23° | 23°°C 0 mm 0% 4 mph 54 % 1015 mb 0 mm/h
Tomorrow 4:00 am
weather icon
20° | 20°°C 0 mm 0% 4 mph 66 % 1014 mb 0 mm/h
Tomorrow 7:00 am
weather icon
24° | 24°°C 0 mm 0% 7 mph 67 % 1015 mb 0 mm/h
Tomorrow 10:00 am
weather icon
27° | 27°°C 0 mm 0% 5 mph 52 % 1015 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
32° | 32°°C 0 mm 0% 4 mph 35 % 1014 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
33° | 33°°C 0 mm 0% 8 mph 27 % 1013 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,259.79
-0.92%
Ethereum(ETH)
€2,086.26
0.16%
Tether(USDT)
€0.85
-0.01%
XRP(XRP)
€1.86
-0.26%
Solana(SOL)
€129.43
0.12%
USDC(USDC)
€0.85
0.01%
Dogecoin(DOGE)
€0.139510
-0.13%
Shiba Inu(SHIB)
€0.000009
-1.87%
Pepe(PEPE)
€0.000009
0.68%
Scroll to Top