STIGQter STIGQter: STIG Summary: Microsoft Exchange 2019 Mailbox Server Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 02 Jul 2025:

The Exchange malware scanning agent must be configured for automatic updates.

DISA Rule

SV-259695r1015277_rule

Vulnerability Number

V-259695

Group Title

SRG-APP-000272

Rule Version

EX19-MB-000147

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

In an elevated Exchange management shell, run the following cmdlet:

Set-MalwareFilteringServer -Identity <Identity> -UpdateFrequency <integer>

Where <Identity> is the name of the Exchange Server and <integer> is the update frequency (in minutes).

Refer to the Enterprise Domain Security Plan (EDSP) for the update cadence that best aligns with the user's organization.

Check Contents

In Exchange Management shell, run the following cmdlet:

Get-MalwareFilteringServer |Select-Object -Property Name, *Update*

If the property "Update frequency" is not set, this is a finding.

If the Malware agent is not installed, then this is not applicable.

Vulnerability Number

V-259695

Documentable

False

Rule Version

EX19-MB-000147

Severity Override Guidance

In Exchange Management shell, run the following cmdlet:

Get-MalwareFilteringServer |Select-Object -Property Name, *Update*

If the property "Update frequency" is not set, this is a finding.

If the Malware agent is not installed, then this is not applicable.

Check Content Reference

M

Target Key

5580