cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who Me Too'd this topic

Alert ID 95501 Microsoft Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

L2 Linker

Hello,

After installing the last content update (https://proditpdownloads.paloaltonetworks.com/content/content-8880-8907.html?__token__=exp=172414152...)

I have a lot of traffic blocked from my servers to the licence microsoft server. But the licence servers get the patch from microsoft (CVE-2024-38077). Does anyone have the same problem ?

 

Other question more technical:  I configured Ip address exemption (licence servers ) on my IPS profile with the 'alert' action for this signature. Could you confirm, if this signature match other servers, traffic will still be blocked?

 

Edit: I have found the answer for IP-address-exemptions behaviour,

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UscCAE

I opened a tac case as well. 

 

Regards,

 

Who Me Too'd this topic