in

eEye Digital Security

The endpoint to vulnerability starts here.

 

Retina came up with vulnerabilities after Windows Update ran and patched system

Last post 10-13-2009 1:36 PM by bpatten. 3 replies.
Page 1 of 1 (4 items)
Sort Posts: Previous Next
  • 10-13-2009 11:54 AM

    Retina came up with vulnerabilities after Windows Update ran and patched system

    Reposting this here as I do not think troubleshooting is the correct forum:

    Ok, so this is the first time I've had an issue like this. I scanned a few servers this morning with updated Audits and I came up with a few vulnerabilities. Well I decided to do a windows update on all of the boxes and now I've got Cumulative IE secuirty updates popping all over my reports. The IE updates and ActiveX killbits appeared "old" but when I looked for more information the site said it was updated as of 10/13/2009....

    I'm going to rollback all of the updates I performed but has anyone else encountered something along the same lines? MS Update screwy?

     

    Thanks

  • 10-13-2009 12:23 PM In reply to

    • bpatten
    • Top 10 Contributor
    • Joined on 09-24-2007
    • Irvine, CA
    • Posts 155

    Re: Retina came up with vulnerabilities after Windows Update ran and patched system

    Today is Patch Tuesday from Microsoft. 10/13/2009.

    Hence patches may affect regex's in certain audits, depending on what changes are made from today's MS updates.

    As a result, we will be releasing new audits for those patches, plus updating existing audits. Updates will come to address those.

  • 10-13-2009 12:37 PM In reply to

    Re: Retina came up with vulnerabilities after Windows Update ran and patched system

     Thank you for the information. It appears I jumped the gun, as I verified after I posted this that the updates were certainly from today. I was however unware of the regex "issue"... How do I provide reasoning for the false positive in this situation without rolling back the updates?

  • 10-13-2009 1:36 PM In reply to

    • bpatten
    • Top 10 Contributor
    • Joined on 09-24-2007
    • Irvine, CA
    • Posts 155

    Re: Retina came up with vulnerabilities after Windows Update ran and patched system

    If you're using Retina, you'll have to look at the Tested and Found values. Those are in the Audit Confirmation Details section of a Vulnerabilities Report.

    You can correlate the Found Values with the patch vendor advisories for the affected versions to prove otherwise. I'm sure your auditor will understand.

Page 1 of 1 (4 items)
© 1995 - 2009 eEye Incorporated