• News/
  • https://www.theregister.com/2024/03/28/germany_microsoft_exchange_patch/

Germany warns of 17,000 unpatched Microsoft Exchange servers

The Register
·
Iain Thomson
·
Published Mar 28, 2024
·
Updated

The German Federal Office for Information Security (BSI) has issued an urgent alert about the poor state of Microsoft Exchange Server patching in the country. The government regulator says there are 17,000 or more Exchange Server instances in Germany vulnerable to at least one critical vulnerability, out of around 45,000 public-facing servers in the Euro nation running the software. Of these servers, 12 percent are running a version of Exchange Server that is ordinarily no longer supported, such as Exchange 2010 and 2013, and around a quarter are running Exchange 2016 and 2019 but without vital patches - meaning at least 37 percent are classed as "vulnerable." "The fact that there are tens of thousands of vulnerable installations of such relevant software in Germany must not happen," warned Claudia Plattner, president of the BSI. "Companies, organizations and authorities unnecessarily endanger their IT systems and thus their added value, their services or their own and third-party data, which may be highly sensitive. Cybersecurity must finally be high on the agenda. There is an urgent need for action!" The BSI is trying to get its citizens to patch early. Just last week Google-owned Mandiant warned that German politicians were under active attack from the Russian Cozy Bear crew, who operate under state sanction from Putin's regime. Of particular concern is fixing CVE-2024-21410, an elevation-of-privilege vulnerability that Microsoft patched last month. According to German inv...

Read full article

Affected Software

4 affected components
Microsoft Exchange Server=2010
Microsoft Exchange Server=2013
Microsoft Exchange Server=2016
Microsoft Exchange Server=2019

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the urgent warning issued by Germany regarding 17,000 unpatched Microsoft Exchange servers.

2

What security implications are discussed in the article?

The article highlights the significant security risks associated with running outdated and unpatched versions of Microsoft Exchange Server.

3

What products or software are affected by the security alert?

The affected software includes multiple versions of Microsoft Exchange Server, specifically 2010, 2013, 2016, and 2019.

4

What has the German Federal Office for Information Security recommended?

The German Federal Office for Information Security has recommended immediate patching of the vulnerable Microsoft Exchange Server instances.

5

Why is it critical to patch Microsoft Exchange Server vulnerabilities?

Patching vulnerabilities in Microsoft Exchange Server is critical to protect against potential cyberattacks and data breaches.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203