<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is CVE-2021-4034 covered by Cortex XDR? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-cve-2021-4034-covered-by-cortex-xdr/m-p/461179#M1493</link>
    <description>&lt;P&gt;Dear fhu_omi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is no content update specifically for&amp;nbsp;&lt;SPAN&gt;CVE-2021-4034 yet but this does not mean that you'll be unprotected. Cortex XDR focuses TTP's and unknowns&amp;nbsp;and You'll be protected by BTP module.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 26 Jan 2022 16:34:11 GMT</pubDate>
    <dc:creator>etugriceri</dc:creator>
    <dc:date>2022-01-26T16:34:11Z</dc:date>
    <item>
      <title>Is CVE-2021-4034 covered by Cortex XDR?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-cve-2021-4034-covered-by-cortex-xdr/m-p/461165#M1492</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;does anyone know if the vulnerability CVE-2021-4034 is covered by Cortex XDR Prevent or Pro?&lt;/P&gt;&lt;P&gt;Source: &lt;STRONG&gt;&lt;A href="https://blog.qualys.com/vulnerabilities-threat-research/2022/01/25/pwnkit-local-privilege-escalation-vulnerability-discovered-in-polkits-pkexec-cve-2021-4034" target="_blank" rel="noopener"&gt;https://blog.qualys.com/vulnerabilities-threat-research/2022/01/25/pwnkit-local-privilege-escalation-vulnerability-discovered-in-polkits-pkexec-cve-2021-4034&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;FH&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 15:35:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-cve-2021-4034-covered-by-cortex-xdr/m-p/461165#M1492</guid>
      <dc:creator>fhu_omi</dc:creator>
      <dc:date>2022-01-26T15:35:35Z</dc:date>
    </item>
    <item>
      <title>Re: Is CVE-2021-4034 covered by Cortex XDR?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-cve-2021-4034-covered-by-cortex-xdr/m-p/461179#M1493</link>
      <description>&lt;P&gt;Dear fhu_omi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is no content update specifically for&amp;nbsp;&lt;SPAN&gt;CVE-2021-4034 yet but this does not mean that you'll be unprotected. Cortex XDR focuses TTP's and unknowns&amp;nbsp;and You'll be protected by BTP module.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 16:34:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-cve-2021-4034-covered-by-cortex-xdr/m-p/461179#M1493</guid>
      <dc:creator>etugriceri</dc:creator>
      <dc:date>2022-01-26T16:34:11Z</dc:date>
    </item>
    <item>
      <title>Re: Is CVE-2021-4034 covered by Cortex XDR?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-cve-2021-4034-covered-by-cortex-xdr/m-p/462045#M1512</link>
      <description>&lt;P&gt;Dear &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/179256"&gt;@etugriceri&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will test it, then we will see if there existing modules will cover this pointer vulnerability. There is a test program out now: &lt;A href="https://pythonrepo.com/repo/kimusan-pkwner" target="_blank"&gt;https://pythonrepo.com/repo/kimusan-pkwner&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jan 2022 07:30:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-cve-2021-4034-covered-by-cortex-xdr/m-p/462045#M1512</guid>
      <dc:creator>fhu_omi</dc:creator>
      <dc:date>2022-01-31T07:30:33Z</dc:date>
    </item>
    <item>
      <title>Re: Is CVE-2021-4034 covered by Cortex XDR?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-cve-2021-4034-covered-by-cortex-xdr/m-p/462861#M1520</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/173884"&gt;@fhu_omi&lt;/a&gt;, did you get a chance to run some tests?&lt;/P&gt;&lt;P&gt;I ran a test on a test environment with XDR pro enabled and the exploit was allowed to execute without tripping anything on Cortex side initially. I did get a wildfire post detection a few hours later.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'd like to hear others feedback for this one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 17:23:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-cve-2021-4034-covered-by-cortex-xdr/m-p/462861#M1520</guid>
      <dc:creator>Luc_Desaulniers</dc:creator>
      <dc:date>2022-02-02T17:23:41Z</dc:date>
    </item>
    <item>
      <title>Re: Is CVE-2021-4034 covered by Cortex XDR?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-cve-2021-4034-covered-by-cortex-xdr/m-p/463238#M1531</link>
      <description>&lt;P&gt;what version and content release is your asset on?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Feb 2022 21:25:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-cve-2021-4034-covered-by-cortex-xdr/m-p/463238#M1531</guid>
      <dc:creator>P.Jacob</dc:creator>
      <dc:date>2022-02-03T21:25:52Z</dc:date>
    </item>
    <item>
      <title>Re: Is CVE-2021-4034 covered by Cortex XDR?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-cve-2021-4034-covered-by-cortex-xdr/m-p/463888#M1538</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/173884"&gt;@fhu_omi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;did some test on this and I'm sharing a couple of sample below. You can play with them better detection or prevention. For the prevention, You need to create BIOC rule and add to Linux restriction profile. I'm sharing for demonstration purposes, might be intrusive and might need find tuning on it before using production. But the point is, even if PANW not shared BIOC via content update, still you can write your own prevention rule.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;For detection&lt;/STRONG&gt;&lt;BR /&gt;preset = xdr_process&lt;BR /&gt;| filter action_process_image_command_line contains "GCONV" and action_process_image_name in ("sh","bash","zsh") and actor_process_image_name = "pkexec" and agent_os_type = ENUM.AGENT_OS_LINUX&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;preset = xdr_process&lt;BR /&gt;| filter action_process_image_command_line contains "GCONV" and action_process_image_name in ("sh","bash","zsh") and agent_os_type = ENUM.AGENT_OS_LINUX&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;for Prevention&lt;/STRONG&gt;&lt;BR /&gt;Process [ action type = execution AND target process cmd = *GCONV* ] AND Host [ host os = linux ]&lt;/P&gt;&lt;P&gt;Process [ action type = execution AND target process cmd = sh*GCONV*sh , bash*GCONV*bash ] AND Host [ host os = linux ]&lt;/P&gt;&lt;P&gt;Process [ action type = execution AND target process name = sh , bash , zsh AND target process cmd = *GCONV* ] AND Host [ host os = linux ]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;(three different sample)&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="etugriceri_0-1644250489517.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39002i679D507FCF62A3D0/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="etugriceri_0-1644250489517.png" alt="etugriceri_0-1644250489517.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Feb 2022 16:18:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/is-cve-2021-4034-covered-by-cortex-xdr/m-p/463888#M1538</guid>
      <dc:creator>etugriceri</dc:creator>
      <dc:date>2022-02-07T16:18:46Z</dc:date>
    </item>
  </channel>
</rss>

