<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CVE-2023-36884 - Does Cortex XDR Pro cover this CVE? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cve-2023-36884-does-cortex-xdr-pro-cover-this-cve/m-p/551520#M4845</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for highlighting. Let me check and will update here on this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank You&lt;/P&gt;</description>
    <pubDate>Fri, 28 Jul 2023 04:42:12 GMT</pubDate>
    <dc:creator>PiyushKohli</dc:creator>
    <dc:date>2023-07-28T04:42:12Z</dc:date>
    <item>
      <title>CVE-2023-36884 - Does Cortex XDR Pro cover this CVE?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cve-2023-36884-does-cortex-xdr-pro-cover-this-cve/m-p/549079#M4748</link>
      <description>&lt;P&gt;Hello dear LIVEcommunity!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Should we follow the recommendation from microsoft or does cortex xdr pro cover this CVE?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.microsoft.com/en-us/security/blog/2023/07/11/storm-0978-attacks-reveal-financial-and-espionage-motives/" target="_blank"&gt;https://www.microsoft.com/en-us/security/blog/2023/07/11/storm-0978-attacks-reveal-financial-and-espionage-motives/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2023 12:26:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cve-2023-36884-does-cortex-xdr-pro-cover-this-cve/m-p/549079#M4748</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2023-07-12T12:26:39Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2023-36884 - Does Cortex XDR Pro cover this CVE?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cve-2023-36884-does-cortex-xdr-pro-cover-this-cve/m-p/549099#M4749</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for writing to live community!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have not yet found any internal updates on the same and would request you to open a support case for coverage assessments. We would be happy to hear from you in circumstance, you get any updates for the same.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please feel free to mark the response as "Accept as Solution" if it answers your query&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2023 12:50:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cve-2023-36884-does-cortex-xdr-pro-cover-this-cve/m-p/549099#M4749</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2023-07-12T12:50:13Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2023-36884 - Does Cortex XDR Pro cover this CVE?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cve-2023-36884-does-cortex-xdr-pro-cover-this-cve/m-p/549171#M4754</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As per some latest updates, you can find updated information on coverage on our unit42 blog post: &amp;nbsp;&lt;A href="https://unit42.paloaltonetworks.com/cve-2023-36884-rce/" target="_blank"&gt;https://unit42.paloaltonetworks.com/cve-2023-36884-rce/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;please mark the response as “Accept as Solution” if it answers your query so that others could navigate to this solution&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jul 2023 03:15:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cve-2023-36884-does-cortex-xdr-pro-cover-this-cve/m-p/549171#M4754</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2023-07-13T03:15:34Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2023-36884 - Does Cortex XDR Pro cover this CVE?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cve-2023-36884-does-cortex-xdr-pro-cover-this-cve/m-p/549420#M4762</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/142551"&gt;@neelrohit&lt;/a&gt;: Thank you very much!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2023 21:01:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cve-2023-36884-does-cortex-xdr-pro-cover-this-cve/m-p/549420#M4762</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2023-07-14T21:01:41Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2023-36884 - Does Cortex XDR Pro cover this CVE?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cve-2023-36884-does-cortex-xdr-pro-cover-this-cve/m-p/551498#M4842</link>
      <description>&lt;P&gt;There are no queries like mentioned in the blog post:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RFeyertag_0-1690497235421.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/52324i4EC35476F28C38CC/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="RFeyertag_0-1690497235421.png" alt="RFeyertag_0-1690497235421.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 22:34:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cve-2023-36884-does-cortex-xdr-pro-cover-this-cve/m-p/551498#M4842</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2023-07-27T22:34:23Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2023-36884 - Does Cortex XDR Pro cover this CVE?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cve-2023-36884-does-cortex-xdr-pro-cover-this-cve/m-p/551520#M4845</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for highlighting. Let me check and will update here on this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank You&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2023 04:42:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cve-2023-36884-does-cortex-xdr-pro-cover-this-cve/m-p/551520#M4845</guid>
      <dc:creator>PiyushKohli</dc:creator>
      <dc:date>2023-07-28T04:42:12Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2023-36884 - Does Cortex XDR Pro cover this CVE?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cve-2023-36884-does-cortex-xdr-pro-cover-this-cve/m-p/551555#M4849</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;These are probably not the queries mentioned in the threat brief but Palo Alto released a XSOAR playbook. In this playbook you can find some XQL hunting queries.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://cortex.marketplace.pan.dev/marketplace/details/CVE_2023_36884__Microsoft_Office_and_Windows_RCE/" target="_blank"&gt;https://cortex.marketplace.pan.dev/marketplace/details/CVE_2023_36884__Microsoft_Office_and_Windows_RCE/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jul 2023 08:56:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cve-2023-36884-does-cortex-xdr-pro-cover-this-cve/m-p/551555#M4849</guid>
      <dc:creator>micomi</dc:creator>
      <dc:date>2023-07-28T08:56:09Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2023-36884 - Does Cortex XDR Pro cover this CVE?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cve-2023-36884-does-cortex-xdr-pro-cover-this-cve/m-p/551682#M4861</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/41187"&gt;@micomi&lt;/a&gt;!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think one of these scripts needs some adjustment (the other Office Applications are missing too):&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RFeyertag_1-1690722159734.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/52362iD9D5F695F5B9C57B/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="RFeyertag_1-1690722159734.png" alt="RFeyertag_1-1690722159734.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Maybe you can forward it to the right people?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rob&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jul 2023 13:04:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cve-2023-36884-does-cortex-xdr-pro-cover-this-cve/m-p/551682#M4861</guid>
      <dc:creator>RFeyertag</dc:creator>
      <dc:date>2023-07-30T13:04:07Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2023-36884 - Does Cortex XDR Pro cover this CVE?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cve-2023-36884-does-cortex-xdr-pro-cover-this-cve/m-p/551717#M4864</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190671"&gt;@RFeyertag&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Good point but I can't forward this to the right people. I'm not from Palo Alto but perhaps someone else can forward this topic&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jul 2023 05:43:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cve-2023-36884-does-cortex-xdr-pro-cover-this-cve/m-p/551717#M4864</guid>
      <dc:creator>micomi</dc:creator>
      <dc:date>2023-07-31T05:43:57Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2023-36884 - Does Cortex XDR Pro cover this CVE?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cve-2023-36884-does-cortex-xdr-pro-cover-this-cve/m-p/552175#M4885</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We've released a fix for that XQL query. Will be available in the marketplace soon.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 10:18:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cve-2023-36884-does-cortex-xdr-pro-cover-this-cve/m-p/552175#M4885</guid>
      <dc:creator>bmelamed</dc:creator>
      <dc:date>2023-08-02T10:18:58Z</dc:date>
    </item>
  </channel>
</rss>

