IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

CBC: Why is the CVE Still Showing After Deploying the Patch?

CBC: Why is the CVE Still Showing After Deploying the Patch?

Environment

  • Carbon Black Cloud:  All Products

Question

The patch for the CVE was deployed; Why is it still showing?

Answer

Troubleshooting steps for Windows endpoints:
   
     1.  Navigate to the specific CVE.   For example:
https://nvd.nist.gov/vuln/detail/CVE-2023-36025#match-10046953
     2.  If a patch is available, then it should be linked from that site.  Continuing with the example: 
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36025
      3.  Locate the OS and KB required to resolve. 
      4.  On the impacted system type:  (KB case sensitive)
dism /online /get-packages | findstr KB2894856

     5.  If the KB is not listed, then it may not be installed and should be installed.

  • Some KB's are included in rollups and may not be searchable the same way;  May require further investigation.

     6.  If the patch was installed, then determine if the Console has had enough time to update the sensor status.

Use Live Query to pull the patch information.

     7.  Please open a CB Support case if Live Query is working, CBC has had time to scan, and the CBC Console continues to report the impacted machine is vulnerable.

 


Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎03-22-2024
Views:
93
Contributors