in

eEye Digital Security

The endpoint to vulnerability starts here.

 

Internet Explorer Vulnerability - False Positive?

Last post 11-17-2009 8:58 PM by bpatten. 5 replies.
Page 1 of 1 (6 items)
Sort Posts: Previous Next
  • 08-03-2009 5:19 PM

    Internet Explorer Vulnerability - False Positive?

    I have recently installed the latest security update for IE7 on my network (Cumulative Security Update for Internet Explorer 7 (KB972260)). Now whenever I do a Retina scan on these machines, they report 2 High risk vulnerabilities:

    Microsoft Internet Explorer Cumulative Security Update (958215) - 2003            Retina Audit ID: 7449
    Microsoft Internet Explorer Security Update (960714) - 2003                              Retina Audit ID: 7521

    or

    Microsoft Internet Explorer Cumulative Security Update (958215) - XP                Retina Audit ID: 7448
    Microsoft Internet Explorer Security Update (960714) - XP                                  Retina Audit ID: 7520

    These vulnerabilities are from 2008, and probably obsolete. I run am running the most updated versions of Win2k3 SP2 and WinXP SP3. Has anyone else had this problem? Does anyone know if these are actually False Positives, or has Microsoft opened up an old vulnerability?

    Thanks

  • 08-04-2009 1:02 PM In reply to

    • bpatten
    • Top 10 Contributor
    • Joined on 09-24-2007
    • Irvine, CA
    • Posts 155

    Re: Internet Explorer Vulnerability - False Positive?

    Hi Jin,

    Both were updated in Audit version 2118 that was released last night.

    Thank you,

    Brian

     

  • 11-10-2009 9:29 AM In reply to

    Re: Internet Explorer Vulnerability - False Positive?

    Hi Brian,

    I am running Audit version 2155 and these two vulnerabiltiies are still appearing on every scan for systems that are fully updated running IE7.

    Thanks for any information,

    Alex

     

     

    Filed under:
  • 11-10-2009 11:57 AM In reply to

    Re: Internet Explorer Vulnerability - False Positive?

     This started with update 2153.  I posted about it, but put down the KB articles as audit ID's.  I wasn't looking at the right number.  Since there was a slew of new updates from Microsoft, I figure the next engine change or audit update should address these findings.

  • 11-17-2009 6:56 AM In reply to

    Re: Internet Explorer Vulnerability - False Positive?

     After update 2159, I was still getting these two findings.  I finally uninstalled then installed the engine.  The findings went away.

  • 11-17-2009 8:58 PM In reply to

    • bpatten
    • Top 10 Contributor
    • Joined on 09-24-2007
    • Irvine, CA
    • Posts 155

    Re: Internet Explorer Vulnerability - False Positive?

    The MS Cumulative Security updates are tricky so when a new version comes out we may alter an existing one (ie latest minus 1) and create a new audit for the new patch, depends on what changes exactly.

    We did make another change from an MS patch in 2157 so that would explain why 2159 worked for you.

Page 1 of 1 (6 items)
© 1995 - 2009 eEye Incorporated