cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2528
Views
10
Helpful
8
Replies

CVE-2022-30190

olfuddyduddy
Level 1
Level 1

Zero Day Exploit of Microsoft Support Diagnostic Tool Detection. What components of Cisco Secure Endpoint will detect and block this vulnerability?

 

https://msrc-blog.microsoft.com/2022/05/30/guidance-for-cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability/ 

8 Replies 8

Armstnei
Level 1
Level 1

I believe they are awaiting a signature update from TALOS to help in detection/prevention.

 

sylvain.hamel1
Level 1
Level 1

They added detection this morning.  I'm just not sure not sure which engine is picking this and if it will only detect or block/quarantine.msdt.png

Behavioral Protection would need to be enabled.

How is it known that this is Behavioral Detection and not Exploit Prevention, Exploit Prevention-Script Control, System Process Protection, or Malicious Activity Protection? Is there a place to look to confirm this?

Hello S.H.,

Thank you for posting this.  If you don't mind sharing a little more, where is this information from?  How do I find this information source for future reference?  Thank you for any assistance you can provide.

 

-  CB

I found it in the Indicators page (Indicators (cisco.com)

 

In Analysis-->Indicators of the console.

msdt2.jpg

 

 

Just sad that they don't have a published/modified date that we could filter on (so that you can see new Indicators added easily....).

Thank you Sylvain. I was able to find the same indicator using general search on "msdt". I'm still trying to determine which AMP detection engine is necessary to be certain this is detecting in my enterprise. The indicator doesn't have that information listed on the indicator blurb. Any clues as to how you determined behavioral engine to be the engine necessory to make use of this indicator?