Microsoft heeft al weer de negentiende Rollup voor het derde service pack van Exchange Server 2010 vrijgegeven. Service Pack 3 werd uitgegeven in februari 2013. De mainstream ondersteuning vanuit Microsoft eindigde in januari 2015, maar de verlengde ondersteuning loopt nog tot januari 2020. In deze verlengde periode worden alleen beveiligings- en tijdzone-updates doorgevoerd. Het bijbehorende KB-artikel met nummer 4035162 vermeldt dat een beveiligingslek verholpen is die kon optreden in een coëxistentie omgeving van Exchange 2010 en Exchange 2016.
Update Rollup 19 for Exchange Server 2010 Service Pack 3
This cumulative update fixes the issue that is described in the following Microsoft Knowledge Base article:Our deployment guidance states when these versions are deployed together, load balancer VIP’s can (should) be pointed to servers running Exchange Server 2016. Exchange Server 2016 will proxy calls to an appropriate server version based upon where the mailbox being accessed is located. We have become aware of a condition which could allow proxied EWS calls to gain access to mailboxes on the 2010 server to which a user should not have access. This issue, tracked by KB4054456, is resolved in Service Pack 3 Update Rollup 19 for Exchange Server 2010. Customers who have deployed Exchange Server 2010 and 2016 together are encouraged to apply Update Rollup 19 with high priority.
- 4054456 EWS connections proxied from Exchange Server 2016 to 2010 can access all the Exchange 2010 mailboxes