diff --git a/docs/Emerging-Issues.md b/docs/Emerging-Issues.md index d507814953..de5448a227 100644 --- a/docs/Emerging-Issues.md +++ b/docs/Emerging-Issues.md @@ -7,34 +7,18 @@ hide: This page lists emerging issues for Exchange On-Premises deployments, possible root cause and solution/workaround to fix the issues. The page will be consistently updated with new issues found and reflect current status of the issues mentioned. -**Updated on 3/10/2023** - -**Issue** | **Products impacted** | **Possible reason**| **Workaround/Solution** --|-|-|- -Uninstall of Exchange servers, that had [January 2023 Security Update](https://techcommunity.microsoft.com/t5/exchange-team-blog/released-january-2023-exchange-server-security-updates/ba-p/3711808) installed at any point in time, fails with error "The operation couldn't be performed because object 'ServerName' couldn't be found on 'DomainControllerName'." | Exchange 2016, Exchange 2019

**Note:**
You can run the [Exchange health checker](https://aka.ms/ExchangeHealthChecker) script to list the security updates installed on the server | Still under investigation | Follow the steps on [this KB article](https://support.microsoft.com/help/5025312) - - - -**Updated on 2/16/2023** - -**Following is list of known issues that can occur after installing [February 2023 Security Update](https://techcommunity.microsoft.com/t5/exchange-team-blog/released-february-2023-exchange-server-security-updates/ba-p/3741058) on Exchange Servers** - -**Issue** | **Products impacted** | **Possible reason**| **Workaround/Solution** --|-|-|- -After installing [February 2023 Security Update](https://techcommunity.microsoft.com/t5/exchange-team-blog/released-february-2023-exchange-server-security-updates/ba-p/3741058), you may observe EWS application pool crash with Event ID 4999 with following error

E12IIS, c-RTL-AMD64, 15.01.2507.021, w3wp#MSExchangeServicesAppPool, M.Exchange.Diagnostics, M.E.D.ChainedSerializationBinder.EnforceBlockReason, M.E.Diagnostics.BlockedDeserializeTypeException, 437c-dumptidset, 15.01.2507.021.

The issue also may cause connectivity issues to EWS based clients like Outlook for Mac | Exchange 2016, Exchange 2019 | Still under investigation | Follow the steps on [this KB article](https://support.microsoft.com/help/5024257) - - -**Updated on 2/15/2023** - -**Following is list of known issues that can occur after installing [January 2023 Security Update](https://techcommunity.microsoft.com/t5/exchange-team-blog/released-january-2023-exchange-server-security-updates/ba-p/3711808) on Exchange Servers** - -**Issue** |**Products impacted** | **Possible reason**| **Workaround/Solution** --|-|-|- -You may find various Exchange commands and scripts (example: RedistributeActiveDatabases.ps1) that use deserialization failing with the error similar to :
Error: "Cannot convert the value of type.....to type". | Exchange 2016
Exchange 2019 | The issue occurs if the [certificate signing for serialization of PowerShell](https://aka.ms/HC-SerializedDataSigning) is enabled and if the auth certificate is not present or has expired | Option 1:
Use the [MonitorExchangeAuthCertificate.ps1](https://aka.ms/MonitorExchangeAuthCertificate) script to update the auth certificate.
Option 2:
Use the steps [here](https://aka.ms/AuthCertRenew) to correct the issue with auth certificate | -RecoverServer may fail at pre-requisites check with following error:
"Exchange Server version Version 15.1 (Build 2507.17) or later must be used to perform a recovery of this server." | Exchange 2016
Exchange 2019 | Resolved | [February 2023](https://support.microsoft.com/help/5023038) and newer SUs will not cause this issue (but modifications made by the January 2023 SU might still require manual action during a server recovery operation). Follow steps on [this article](https://learn.microsoft.com/exchange/troubleshoot/setup/version-error-in-recover-server-mode-install) to fix the issue. | -The Exchange services in Automatic start-up mode will not start after reboot of the server. The services start successfully if started manually | Exchange 2016 installed on Windows 2012 R2, other versions are not affected | Resolved | Install the [February 2023 Exchange Server Security Updates](https://support.microsoft.com/help/5023038) to fix the issue | -The Exchange toolbox may start crashing on launch after [certificate Serialization for PowerShell](https://aka.ms/HC-SerializedDataSigning) is enabled. The error noticed is "Deserialization fails: System.Reflection.TargetInvocationException".|Exchange 2016
Exchange 2019 | Under investigation | Use one of the workarounds described in [this article](https://support.microsoft.com/help/5023352) -Get-ExchangeCertificate command may not list any certificates | Exchange 2016
Exchange 2019
| Under investigation | Launch the Exchange management shell in elevated mode and then use Get-ExchangeCertificate command +|**Updated on** | **Update causing the issue**| **Issue**| **Workaround/Solution** +|-|-|-|-| +|3/16/2023| [Outlook client update for CVE-2023-23397 released](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23397)| These vulnerabilities affect Exchange Server. Exchange Online customers are already protected from the vulnerabilities addressed in these SUs and do not need to take any action **other than updating Exchange servers in their environment, and if applicable, installing the security update for Outlook on Windows described on the link on the right.**
More details about specific CVEs can be found in the [Security Update Guide](https://msrc.microsoft.com/update-guide/) (filter on Exchange Server under Product Family).
**Awareness: Outlook client update for CVE-2023-23397 released**
There is a critical security update for Microsoft Outlook for Windows that is required to address [CVE-2023-23397](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23397). To address this CVE, **you must install the Outlook security update, regardless of where your mail is hosted (e.g., Exchange Online, Exchange Server, some other platform).** | **Please check [this page](https://aka.ms/OLKCVEFAQ) for FAQs about the [Outlook CVE-2023-23397](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23397)** +3/14/2023|[February 2023 Security Update](https://techcommunity.microsoft.com/t5/exchange-team-blog/released-february-2023-exchange-server-security-updates/ba-p/3741058) for Exchange 2016, Exchange 2019, Exchange 2013 | After installing February 2023 security update, customers are seeing EWS application pool crash with Event ID 4999 with following error

E12IIS, c-RTL-AMD64, 15.01.2507.021, w3wp#MSExchangeServicesAppPool, M.Exchange.Diagnostics, M.E.D.ChainedSerializationBinder.EnforceBlockReason, M.E.Diagnostics.BlockedDeserializeTypeException, 437c-dumptidset, 15.01.2507.021.

The issue is causing connectivity issues to EWS based clients (Outlook for Mac) | **Update on 3/14/2023**
The issue is fixed in [March 2023 security update for Exchange servers](https://techcommunity.microsoft.com/t5/exchange-team-blog/released-march-2023-exchange-server-security-updates/ba-p/3764224)
Please follow the steps in [this KB](https://support.microsoft.com/help/5024257) +3/14/2023|[February 2023 Security Update](https://techcommunity.microsoft.com/t5/exchange-team-blog/released-february-2023-exchange-server-security-updates/ba-p/3741058) for Exchange 2016, Exchange 2019, Exchange 2013 | Some customers are reporting issues with Outlook/OWA add-ins, like add-in not listing in EAC or with the Get-App command. Additionally, they may notice EWS application pool crash with Event ID 4999 in the application log of the Exchange server. | **Update on 3/14/2023**
The issue is fixed in [March 2023 security update for Exchange servers](https://techcommunity.microsoft.com/t5/exchange-team-blog/released-march-2023-exchange-server-security-updates/ba-p/3764224) +3/14/2023|[January 2023 Security Update](https://www.microsoft.com/en-us/download/details.aspx?id=104914) for Exchange 2016, Exchange 2019 |The Exchange toolbox may start crashing on launch after [certificate Serialization for PowerShell](https://aka.ms/HC-SerializedDataSigning) is enabled. The error noticed is "Deserialization fails: System.Reflection.TargetInvocationException".

The issue happens only on Exchange 2016 and Exchange 2019| **Update on 3/14/2023**
The issue is fixed in [March 2023 security update for Exchange servers](https://techcommunity.microsoft.com/t5/exchange-team-blog/released-march-2023-exchange-server-security-updates/ba-p/3764224) +3/10/2023|[January 2023 Security Update](https://www.microsoft.com/en-us/download/details.aspx?id=104914) for Exchange 2016, Exchange 2019 | When you try to uninstall Microsoft Exchange Server 2019 or 2016 on servers, that had January 2023 Security Update for Exchange Server installed at any point, the Setup fails with following error message:

[ERROR] The operation couldn't be performed because object '' couldn't be found on ''. | Follow the steps from [this KB](https://support.microsoft.com/help/5025312) +|-|-|-|- |-|-| +1/24/2023|[January 2023 Security Update](https://www.microsoft.com/en-us/download/details.aspx?id=104914) for Exchange 2016, Exchange 2019 | After installing January 2023 security update and enabling [certificate signing for serialization of PowerShell](https://aka.ms/HC-SerializedDataSigning), you may find various Exchange commands and scripts (example: RedistributeActiveDatabases.ps1) that use deserialization failing with the error similar to :
Error: "Cannot convert the value of type.....to type" | Use [this script](https://aka.ms/MonitorExchangeAuthCertificate) to update the auth certificate +1/24/2023|[January 2023 Security Update](https://www.microsoft.com/en-us/download/details.aspx?id=104914) for Exchange 2016, Exchange 2019 | RecoverServer will fail at pre-requisites check with following error:
"Exchange Server version Version 15.1 (Build 2507.17) or later must be used to perform a recovery of this server." | **Update on 02/23/2023**
The issue has been fixed in [February 2023 Security Update for Exchange servers](https://support.microsoft.com/KB/5023038), however, the following workaround still needs to be used for servers that are on January 2023 Security Update

**Workaround**
Use the steps in [this](https://learn.microsoft.com/exchange/troubleshoot/setup/version-error-in-recover-server-mode-install) article +1/24/2023|[January 2023 Security Update](https://www.microsoft.com/en-us/download/details.aspx?id=104914) for Exchange 2016 installed on Windows 2012 R2, other versions are not affected |The Exchange services in Automatic start-up mode will not start after reboot of the server. The services start successfully if started manually| **Update on 02/23/2023**
The issue has been fixed in [February 2023 Security Update for Exchange servers](https://support.microsoft.com/KB/5023038) +1/24/2023|[January 2023 Security Update](https://www.microsoft.com/en-us/download/details.aspx?id=104914) for Exchange 2016, Exchange 2019 | Transport header shows the older version of server once January 2023 SU is installed (the build shown seems to be the build of the last CU) | The issue will be addressed in upcoming security update |