A flaw affecting servers running Microsoft Exchange prevented emails sent at the start of the new year from arriving.
When the date changed from 2021 to 2022 at midnight, emails were added to a queue instead of being sent, resulting in them becoming stuck.
The reason for the delays was down to a flaw in how Microsoft Exchange manages updates for its malware scanning engine. These use a year-month-day system, plus another four numbers. This means that the number required to display January 1, 2022 was 2,201,010,001.
However, the system stores dates as 32-bit binary integers, meaning the maximum number the system can use is 2,147,483,647. As such, when the system looked for the latest malware update, the version past January 1, 2022 exceeded the largest number, causing the system to crash.
The flaw affected on-premises servers running Exchange Server 2016 and Exchange Server 2019.
Microsoft Exchange is an application developed by Microsoft to operate mail and calendaring servers, most frequently used by businesses and other large organisations.
The bug was fixed by Microsoft in an emergency patch on January 1. Users of Microsoft Exchange will need to download the fix to ensure emails send as normal.
Recommended
- Contributed | 5 Scottish tech trends for 2022
- The NHS app has exceeded 22m users in major milestone
- New malware exploits Microsoft’s e-Signature verification
Microsoft noted that the bug did not represent a cybersecurity threat to users.
“The problem relates to a date check failure with the change of the new year and it not a failure of the AV engine itself. This is not an issue with malware scanning or the malware engine, and it is not a security-related issue,” the company said in a statement.
Microsoft Exchange was previously at the heart of a major security breach at the start of last year, one so major US President Joe Biden created a task force to investigate it.
A zero-day flaw was discovered affecting unpatched servers running Exchange. This led to a wave of attacks looking to exploit the vulnerability, along with a new strain of ransomware.





