Free tools Windows power users keep installed
One-click scans. No signup required.
Microsoft temporarily withdrew the November 12, 2024 security updates for on-premises Exchange Server 2016 and 2019 after administrators reported that Exchange Transport Rules and Data Loss Prevention (DLP) rules stopped processing, disrupting mail flow. The original package, KB5044062, was later corrected and re-released as KB5049233 on November 27, 2024. This was a resolved, configuration-dependent incident—not a continuing Exchange Online outage or a permanent cancellation of Exchange security updates.
What Microsoft pulled
The affected release was Microsoft’s November 2024 security update for Exchange Server 2016 and Exchange Server 2019, issued on November 12, 2024 as KB5044062. After reports of mail-flow failures, Microsoft paused its distribution through Windows Update/Microsoft Update and removed the package from the Microsoft Download Center while it investigated. The withdrawal was temporary; Microsoft later issued a corrected package. Microsoft’s original update documentation is at KB5044062, and the withdrawal was reported by BleepingComputer.
This did not mean Microsoft abandoned Exchange security servicing. It was an emergency stop to a defective release while a fix was prepared.
What broke
The documented defect caused Exchange to stop processing Exchange Transport Rules (ETR) and DLP rules. These rules operate in the transport pipeline and can inspect, classify, redirect, reject, or otherwise modify messages. When processing failed, an organization could see delayed, rejected, misrouted, or stalled mail, depending on its rule configuration.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
The issue was not established as a universal SMTP failure. Microsoft’s description concerns rule processing, and reports focused on servers that used transport or DLP rules. A server without those rules—or one that had the update installed but showed no symptoms—was not automatically in the same failure state.
Which installations were in scope
| Installation or update | Relevance |
|---|---|
| Exchange Server 2016 | Directly in scope for the November 12, 2024 update and its rule-processing defect. |
| Exchange Server 2019 | Directly in scope for the November 12, 2024 update and its rule-processing defect. |
| Exchange Online | Not the subject of this on-premises update withdrawal; do not treat the incident as a Microsoft 365 service outage. |
| Hybrid deployment | On-premises Exchange servers still require patching even when mailboxes are hosted in Exchange Online. |
The original support material referenced applicable cumulative-update baselines, including Exchange 2019 CU13/CU14 and Exchange 2016 CU23. Administrators should check the support page for the exact cumulative-update baseline rather than assuming every historical CU used an identical package.
Rank #2
Microsoft’s update FAQ says hybrid organizations must keep their on-premises Exchange servers current: Exchange Server update FAQ.
What administrators were told to do
The emergency response depended on symptoms and configuration. Use this sequence when investigating an affected server:
- Identify the installed update. Confirm whether KB5044062, or a later corrected package, is installed and record its installation time.
- Check the affected features. Inventory Exchange Transport Rules and DLP rules, including rules that redirect, reject, classify, or quarantine messages.
- Compare symptoms with timing. Review transport queues, message-tracking results, delivery delays, rejects, and rule actions. Preserve relevant logs before making changes.
- Restore service if the update is the confirmed cause. Microsoft’s contemporaneous guidance was to uninstall the faulty November update when it caused mail-flow problems. The available guidance does not establish one universal PowerShell or DISM rollback command for every Exchange topology, so use your organization’s approved change and recovery procedure.
- Install the corrected release. After operational testing, deploy Microsoft’s re-released update or a later applicable cumulative/security update.
- Validate before closing the incident. Send representative internal and external test messages, exercise transport and DLP rules, inspect queues, and confirm expected message-tracking events.
Organizations that did not use transport or DLP rules and were not seeing mail-flow problems were not told to uninstall solely because the incident existed; the reported guidance allowed them to continue running the update while Microsoft worked on the correction. See the contemporaneous account at BleepingComputer.
Why uninstalling a security update created a trade-off
KB5044062 also addressed Exchange security issues, including CVE-2024-49040. Microsoft described this issue as involving non-RFC-compliant P2 FROM headers that could make a forged sender appear legitimate in a mail client such as Outlook. The update added detection and warning behavior for certain malformed messages. The available reporting does not support describing CVE-2024-49040 as a universal remote-code-execution or account-takeover flaw.
That created a practical dilemma:
- Leaving the defective update installed could disrupt transport and DLP processing.
- Removing it could restore mail flow but temporarily leave the server without the update’s security fixes.
- The safe long-term resolution was to move to Microsoft’s corrected release, not to remain rolled back.
Incident timeline
| Date | Event |
|---|---|
| November 12, 2024 | Microsoft released the Exchange Server 2016/2019 security update KB5044062. |
| November 12–15, 2024 | Administrators reported mail-flow failures associated with custom transport and DLP rules. |
| November 15, 2024 | Microsoft paused distribution through Windows/Microsoft Update and removed the package from the Download Center; affected administrators were advised to uninstall it. |
| November 27, 2024 | Microsoft re-released a corrected version, identified on the original support page as KB5049233. The re-release addressed the rule-processing defect. |
| August 18, 2026 | The event is historical and resolved. Current patch decisions should use the administrator’s Exchange version and the latest applicable Microsoft guidance. |
The later re-release is also reported in BleepingComputer’s follow-up.
What to verify on Exchange servers now
Do not use the 2024 rollback advice as a current patching plan. Instead, establish the server’s present state:
- Confirm the Exchange Server major version and cumulative update.
- Confirm that the corrected update or a later applicable security update is installed, rather than relying only on the KB5044062 label.
- Test representative Exchange Transport Rules and DLP rules, including rejection, redirection, classification, and quarantine actions used by the organization.
- Review message queues and message-tracking results for unexplained delays or rejects.
- Run Microsoft’s Exchange Health Checker before and after update work; Microsoft’s update FAQ describes it as a way to identify missing updates and follow-up actions.
- For hybrid environments, verify the on-premises servers as well as cloud-side service health. Mailboxes in Exchange Online do not remove the need to maintain on-premises Exchange components.
Exchange security updates are cumulative-update-specific. Microsoft recommends installing the latest supported cumulative update, then the latest applicable security update, and using Health Checker to confirm the result. Follow the current procedures in the Microsoft Exchange Server update FAQ.
Quick Recap
What this incident does—and does not—mean
- It means a November 2024 on-premises Exchange security release had a rule-processing defect serious enough to cause mail-flow problems in affected configurations.
- It does not mean every Exchange server lost all mail delivery.
- It does not describe an Exchange Online outage.
- It does not mean Microsoft permanently canceled Exchange security updates.
- It does mean administrators should treat mail-flow testing as part of Exchange patch validation, not merely check whether Exchange services are running.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




