Skip to content

Release#390

Merged
bill-long merged 18 commits into
releasefrom
main
Mar 18, 2021
Merged

Release#390
bill-long merged 18 commits into
releasefrom
main

Conversation

@bill-long
Copy link
Copy Markdown
Member

No description provided.

SharmaAkash1 and others added 10 commits March 18, 2021 21:26
The changes made in the script are as follows:

1.	For  Cve26858 we only show the error if the path in the error message “Download failed and temporary file <path> needs to be removed” is invalid (does not start with C:\Program Files\Microsoft\Exchange Server\V15\ClientAccess\OAB)
2.	For set-virtual directory we throw an error only if the url is invalid
3.	For the get-suspicious files we only show those if one of the 4 vulnerabilities (Cve26855 Or  Cve26857 or  Cve26858 or  Cve27065 ) is found.
This was done because even customers who did not have any vulnerabilities were alerted due to the presence of some zip files that they had created in their system.
These false positives lead to a lot of confusion and the uneasiness for the customers.
4.	We also show an additional error message regarding web shells if we find logs of successful reset-virtualdirectory hits (having a bad anchor mailbox object) in the httpsproxy folder.
Fix sorting in release description
Adding changes to reduce false positives seen by customers
Make script names download links for that release
@bill-long bill-long requested a review from dpaulson45 March 18, 2021 18:27
@bill-long bill-long merged commit 248d7e3 into release Mar 18, 2021
dpaulson45 added a commit that referenced this pull request Apr 20, 2021
November 2020 Security Updates (SU) added
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants