Hello,
We are updating february hotfix on ENS 10.6.1.1208 and 10.6.1.1128 and we are getting the following alert from ePO:
Event Category: | 'File' class or access |
Event ID: | 18060 |
Threat Severity: | Critical |
Threat Name: | Windows Shell Remote Code Execution Vulnerability |
Threat Type: | Exploit Prevention |
Action Taken: | Would block |
Threat Handled: | TRUE |
Analyzer Detection Method: | Exploit Prevention |
Events received from managed systems | |
Event Description: | Exploit Prevention Files/Process/Registry violation detected |
We have update 950 systems so far and getting this alert from around 200 systems after the hotfix is installed.
In all cases the source process name is winword, powerpoint, excel exes and the threat target file path is C:\USERS\*username*\APPDATA\LOCAL\TEMP\DEPLOYMENT.
Is anyone experienced this issue?
Thank you for your answers.
Best Regards
Zebu
Solved! Go to Solution.
@NimrodMiz If your rule is set to report only, and you would no longer like to see the reported events, you could turn off reporting of the rule.
If that is not the situation, please provide some additional details to the context of the situation in which this behavior is occurring, so we could make a more tailored recommendation. If you'd like detailed review of the logs in order to reach that end, then I would recommend that you reach out to Technical Support for assistance in review.
Was my reply helpful?
If this information was helpful in any way, or answered your question, will you please select "Accept as Solution" in my reply, or give kudos as appropriate, so together we can help other members?
Hey,
I am experiencing this issue as well, with May Update.
What can we do about this?
Thanks,
Nimrod.
@NimrodMiz If your rule is set to report only, and you would no longer like to see the reported events, you could turn off reporting of the rule.
If that is not the situation, please provide some additional details to the context of the situation in which this behavior is occurring, so we could make a more tailored recommendation. If you'd like detailed review of the logs in order to reach that end, then I would recommend that you reach out to Technical Support for assistance in review.
Was my reply helpful?
If this information was helpful in any way, or answered your question, will you please select "Accept as Solution" in my reply, or give kudos as appropriate, so together we can help other members?
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA