<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cortex XDR: iexplorer.exe execution triggers the Memory Corruption Exploit Module in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-iexplorer-exe-execution-triggers-the-memory/m-p/411203#M784</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am having this problem in a host managed by Cortex XDR , whenever I execute iexplorer.exe or outlook an xdr agent alarm is triggered indicating that it's a Memory Corruption Exploit. Except creating an Exploit profile and excluding this kind of alarm , is there any other solution , has anyone the same problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Process blocked: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:6220 CREDAT:18363609 /prefetch:2&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 04 Jun 2021 14:27:04 GMT</pubDate>
    <dc:creator>service-ad</dc:creator>
    <dc:date>2021-06-04T14:27:04Z</dc:date>
    <item>
      <title>Cortex XDR: iexplorer.exe execution triggers the Memory Corruption Exploit Module</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-iexplorer-exe-execution-triggers-the-memory/m-p/411203#M784</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am having this problem in a host managed by Cortex XDR , whenever I execute iexplorer.exe or outlook an xdr agent alarm is triggered indicating that it's a Memory Corruption Exploit. Except creating an Exploit profile and excluding this kind of alarm , is there any other solution , has anyone the same problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Process blocked: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:6220 CREDAT:18363609 /prefetch:2&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jun 2021 14:27:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-iexplorer-exe-execution-triggers-the-memory/m-p/411203#M784</guid>
      <dc:creator>service-ad</dc:creator>
      <dc:date>2021-06-04T14:27:04Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR: iexplorer.exe execution triggers the Memory Corruption Exploit Module</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-iexplorer-exe-execution-triggers-the-memory/m-p/413545#M803</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/117"&gt;@service-ad&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am having this problem in a host managed by Cortex XDR , whenever I execute iexplorer.exe or outlook an xdr agent alarm is triggered indicating that it's a Memory Corruption Exploit. Except creating an Exploit profile and excluding this kind of alarm , is there any other solution , has anyone the same problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Process blocked: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:6220 CREDAT:18363609 /prefetch:2&lt;/SPAN&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Sounds like what you need to do is &lt;A href="https://docs.paloaltonetworks.com/cortex/cortex-xdr/cortex-xdr-prevent-admin/investigation-and-response/investigate-endpoint-alerts/manage-alerts.html#id28f60556-5235-4f96-8bf6-0de0dbc94925_idd207d385-46d0-4fb3-b6e5-493bdc5d8678" target="_self"&gt;retrieve and analyze,&lt;/A&gt;&amp;nbsp;If this doesn't work, solution will be to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;download the retrieve data and submit for&amp;nbsp;&lt;/SPAN&gt;analysis of the issue by the Support team.&lt;/P&gt;&lt;P&gt;They can be reached at&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://support.paloaltonetworks.com/" target="_blank" rel="nofollow noopener noreferrer"&gt;https://support.paloaltonetworks.com/&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jun 2021 12:18:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-iexplorer-exe-execution-triggers-the-memory/m-p/413545#M803</guid>
      <dc:creator>zsolomon</dc:creator>
      <dc:date>2021-06-16T12:18:59Z</dc:date>
    </item>
  </channel>
</rss>

