Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Issue] - Health Checker - CVE-2023-36434 Vulnerability message on server 2025 #2255

Open
StiflersM0M opened this issue Dec 12, 2024 · 4 comments
Assignees
Labels
By Design / No issue The behavior described is by design. Health Checker

Comments

@StiflersM0M
Copy link

Provide Version Number
Newest available on 12.12.2024
Version: Exchange 2019 CU14 Nov24SUv2
Build Number: 15.02.1544.014

Describe the issue
Health Checker shows that the Server is vulnerable for CVE-2023-36434. But CVE states that Server 2025 isnt affected by the vulnerablility (therefore there is also no Fix/Update available).

Expected behavior
Seems like a false positive on Server 2025, so Health Checker shouldnt show this as a detected vulnerablility.

Additional context
Server was upgraded (inplace upgrade) from 2022 to 2025. At the time of the update, KB5031364 (Fixing update) was allready installed on server 2022.

Image

@lusassl-msft
Copy link
Contributor

lusassl-msft commented Dec 12, 2024

@StiflersM0M

Windows Server 2025 is not a supported operating system (OS) for running Exchange Server. Therefore, we do not have any logic in place to check for the OS version concerning this CVE. For more details, please refer to https://learn.microsoft.com/en-us/exchange/plan-and-deploy/supportability-matrix?view=exchserver-2019#supported-operating-systems. Additionally, OS in-place upgrades are not supported.

@lusassl-msft lusassl-msft added By Design / No issue The behavior described is by design. and removed Issue labels Dec 12, 2024
@dpaulson45
Copy link
Member

We do need to check into this for Exchange 2019 CU15 where this is supported and make sure there isn't an issue there.

@dpaulson45
Copy link
Member

@StiflersM0M thanks for reporting this. However, as of right now, Exchange 2019 is not supported with Windows Server 2025 until CU15. That being said, we do need to adjust the code to account for Windows Server 2025+ on this check.

20348 { $tokenCacheFixedVersionNumber = "10.0.20348.2029"; break } # Windows Server 2022

@dpaulson45
Copy link
Member

This issue has been addressed internally and will be resolved when Exchange CU15 is released and is actually supported with Windows Server 2025. This issue will be closed at that time.

@dpaulson45 dpaulson45 self-assigned this Jan 16, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
By Design / No issue The behavior described is by design. Health Checker
Projects
None yet
Development

No branches or pull requests

3 participants