<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unpatched Vulnerabilities Protection in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/unpatched-vulnerabilities-protection/m-p/1228463#M8292</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I see this written in Unpartched vulnerability protection module section "&lt;SPAN&gt;Modify system settings temporarily as a workaround to protect unpatched endpoints from known vulnerabilities".&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I have searched but found no details regarding this, can anyone please explain how does this work?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Also, is there any protection against 0 day vulnerabilities in cortex?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 08 May 2025 09:10:24 GMT</pubDate>
    <dc:creator>Abdullah-Tariq</dc:creator>
    <dc:date>2025-05-08T09:10:24Z</dc:date>
    <item>
      <title>Unpatched Vulnerabilities Protection</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/unpatched-vulnerabilities-protection/m-p/1228463#M8292</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I see this written in Unpartched vulnerability protection module section "&lt;SPAN&gt;Modify system settings temporarily as a workaround to protect unpatched endpoints from known vulnerabilities".&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I have searched but found no details regarding this, can anyone please explain how does this work?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Also, is there any protection against 0 day vulnerabilities in cortex?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 May 2025 09:10:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/unpatched-vulnerabilities-protection/m-p/1228463#M8292</guid>
      <dc:creator>Abdullah-Tariq</dc:creator>
      <dc:date>2025-05-08T09:10:24Z</dc:date>
    </item>
    <item>
      <title>Re: Unpatched Vulnerabilities Protection</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/unpatched-vulnerabilities-protection/m-p/1228913#M8297</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/870588881"&gt;@Abdullah-Tariq&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;This step provides a temporary workaround for the following publicly known information-security vulnerabilities and exposures: CVE-2021-24074, CVE-2021-24086 and CVE-2021-24094.&lt;/P&gt;
&lt;P&gt;If you choose not to patch the endpoint, the Unpatched Vulnerabilities Protection capability allows the Cortex XDR agent to apply a workaround to protect the endpoints from the known vulnerability. It takes the Cortex XDR agent up to 6 hours to enforce your configured policy on the endpoints.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Refer to step 7 in below article for more information:&lt;BR /&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Set-up-exploit-prevention-profiles" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Set-up-exploit-prevention-profiles&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Yes, to an extent. Cortex XDR uses several capabilities to provide proactive protection against unknown threats, including 0-days:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Behavioral Threat Protection (BTP):&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Detects malicious behaviors and attack patterns, regardless of file signatures.&lt;/P&gt;
&lt;P&gt;Can block suspicious activity even from unknown exploits.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Exploit Protection &amp;amp; Module Load Protection:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Intercepts suspicious exploit techniques such as memory corruption, code injection, etc.&lt;/P&gt;
&lt;P&gt;Effective against many 0-day exploits, especially those targeting known vectors.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;AI-Driven Local Analysis and WildFire Integration:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Uses static and dynamic analysis to detect new, unknown malware.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Analytic Rules &amp;amp; BIOC (Behavioral Indicators of Compromise):&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Detects advanced tactics even without specific IOCs.&lt;/P&gt;
&lt;P&gt;However:&lt;/P&gt;
&lt;P&gt;No solution can guarantee 100% protection against all zero-day attacks, but Cortex XDR significantly reduces risk by combining multiple protection layers and telemetry-based analytics.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you feel this has answered your query, please let us know by clicking like and&amp;nbsp; on "mark this as a Solution". Thank you.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 May 2025 06:21:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/unpatched-vulnerabilities-protection/m-p/1228913#M8297</guid>
      <dc:creator>aspatil</dc:creator>
      <dc:date>2025-05-13T06:21:22Z</dc:date>
    </item>
    <item>
      <title>Re: Unpatched Vulnerabilities Protection</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/unpatched-vulnerabilities-protection/m-p/1229045#M8303</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/308232"&gt;@aspatil&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/870588881"&gt;@Abdullah-Tariq&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;This step provides a temporary workaround for the following publicly known information-security vulnerabilities and exposures: CVE-2021-24074, CVE-2021-24086 and CVE-2021-24094.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;So it is for only these CVE, no other known vulnerability?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And as for patching, i ask because some solutions like trend micro deep security claim to provide virtual patching capabilities. I was just trying to compare cortex to that.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 May 2025 08:40:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/unpatched-vulnerabilities-protection/m-p/1229045#M8303</guid>
      <dc:creator>Abdullah-Tariq</dc:creator>
      <dc:date>2025-05-14T08:40:22Z</dc:date>
    </item>
  </channel>
</rss>

