What is the downside of enabling "Download Domains" to remediate CVE-2021-1730?

Jax Planet 61 Reputation points
2021-09-30T16:36:26.23+00:00

The HealthChecker.PS1 script reports that not having "Download Domains" makes an Exchange server vulnerable to CVE-2021-1730 (See: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-1730).

It looks simple to implement but I can't find any information describing the side-effects of implementing it.

Is there any downside to setting up a Download Domain?

Thank you in advance.

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,363 questions
{count} votes

Accepted answer
  1. Xzsssss 8,861 Reputation points Microsoft Vendor
    2021-10-01T01:20:54.753+00:00

    Hi @Jax Planet ,

    It's like the download domain is only used to download items from OWA browsers. Basically you don't have to install other softwares or something to enable it.

    Even though the official document has nothing useful:
    136806-image.png
    I think you don't have to worry about that.

    See this discuss: https://www.reddit.com/r/exchangeserver/comments/onhchg/download_domains_cve20211730_and_microsoft/
    Please Note: Since the web site is not hosted by Microsoft, the link may change without notice. Microsoft does not guarantee the accuracy of this information.

    Best regards,
    Lou


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

2 additional answers

Sort by: Most helpful
  1. Jax Planet 61 Reputation points
    2021-11-05T02:53:14.8+00:00

    Thanks again!

    I completely agree that this level of complexity can yield unexpected results.

    I will test it on a non-production server first.

    If I find any problem in pre or post production, I will post back.

    1 person found this answer helpful.

  2. Jax Planet 61 Reputation points
    2021-10-01T01:51:53.003+00:00

    Thank you for the fast reply!

    If I understand you correctly, you don't foresee any problems with making this change.

    Regardless, I would like some way to make sure it did not cause a problem.

    If I can download attachments in OWA after this change, does it mean that everything is okay?