07-08-2021 08:40 AM
We've configured a Vulnerability profile with the Action of Default. For the Windows Print night mare vulnerability (Version ID: 8424, signature ID:91333) and the CVE ID: CVE-2021-1675 I see the default action is marked as 'Alert' which will allow the traffic.
I am trying to change the action of an specific Vulnerability signature from Alert to Block. When I go to the profile and find the signature in the Exceptions and change it to Block. If I click on enable and Click OK, this specific one is showing under the 'exceptions' tab as expected.
Will it be exempted from the traffic processing? Am I missing something?
How do I change the default behavior of only this signature to be reset ?
Thanks in advance
91333 Windows Print Spooler Remote Code Execution Vulnerability CVE-2021-1675 code-execution alert 7.1.0
07-08-2021 11:44 AM
So if you pull the latest updates these have actually been modified away from Alert and to reset-server, but as an FYI you would want to apply the same action to all three IDs (91333, 91346, 91349) to be fully covered.
Create a new rule on your Vulnerability protection profile that specifies CVE-2021-1675 with the action set to however you want. This will override all signatures that are created for CVE-2021-1675 and apply the desired action.
07-11-2021 07:53 AM
Many thanks for the reply.
If I'm not wrong, we'll create an custom rule just for this CVE (with the specific action: reset-both) and add it to the existing Vulnerability Protection Profile.
If yes, can you please let me know how this is different from changing the default action of this CVE to reset-both under the exceptions tab? Is it same or different?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!