Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

wesng shows ridiculous amount of vulnerabilities #68

Closed
Warlord711 opened this issue Oct 20, 2022 · 1 comment
Closed

wesng shows ridiculous amount of vulnerabilities #68

Warlord711 opened this issue Oct 20, 2022 · 1 comment

Comments

@Warlord711
Copy link

Warlord711 commented Oct 20, 2022

2022-10-20 23_27_58-Kali_Neu  wird ausgeführt  - Oracle VM VirtualBox
Got a systeminfo.txt from a Win Server 2012 R2 with 220 Hotfixes installed, wesng shows oder 9000 vulnerabilites.
A lot of them are for different systems like Win10/7, also comes with tons of duplicates.

I used

./wes.py systeminfo.txt --exploits-only --hide "Internet Explorer" Edge Flash --muc-lookup

systeminfo.txt
2022-10-20 23_23_28-Kali_Neu  wird ausgeführt  - Oracle VM VirtualBox

@bitsadmin
Copy link
Owner

Thanks @Warlord711 for your report.

Unfortunately we are dependent on the (incomplete) supersedence information provided by Microsoft. The --muc-lookup feature attempts to remove false positives, but is also not fool proof. The only option is then to manually validate the supposedly missing KBs to see if they have actually been superseded by a KB that is installed. For more info, see the blog: https://blog.bitsadmin.com/blog/windows-security-updates-for-hackers#eliminating-false-positives.

An alternative is to use the missingkbs.vbs script also available in this repository, to have Windows update identify the missing KBs.

In case you identified an error in the logic of wes.py, please elaborate.

Hope that helps!

Best,
Arris

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants