Skip to content

CVE-2021-34470 check improved#648

Merged
dpaulson45 merged 1 commit into
mainfrom
lusassl-June21SUWordingFix
Jul 28, 2021
Merged

CVE-2021-34470 check improved#648
dpaulson45 merged 1 commit into
mainfrom
lusassl-June21SUWordingFix

Conversation

@lusassl-msft
Copy link
Copy Markdown
Contributor

@lusassl-msft lusassl-msft commented Jul 27, 2021

Issue:
CVE-2021-34470 check improved to address #646.

Reason:
It drives confusion if we show that the system is vulnerable to CVE-2021-34470 even if the SU has been installed.

Fix:
We now check if KB5004778 or KB5004779 or KB5004780 are in place. If that's the case, we perform testing against the schema and check for the required schema change. If the schema change has not been performed, we highlight that /PrepareSchema is required to finalize the July 2021 SU installation to become fully protected against CVE-2021-34470.

Validation:
Lab

Comment thread Diagnostics/HealthChecker/Analyzer/Invoke-AnalyzerEngine.ps1 Outdated
@lusassl-msft lusassl-msft force-pushed the lusassl-June21SUWordingFix branch from bb1b416 to bc82375 Compare July 28, 2021 09:21
@lusassl-msft lusassl-msft requested a review from dpaulson45 July 28, 2021 09:25
@lusassl-msft lusassl-msft force-pushed the lusassl-June21SUWordingFix branch from c926edd to ce8769f Compare July 28, 2021 09:41
Using build number to check for patchlevel

Some more adjustments

We only check the build for E15 now.
@lusassl-msft lusassl-msft force-pushed the lusassl-June21SUWordingFix branch from ce8769f to fc66bf4 Compare July 28, 2021 16:02
@dpaulson45 dpaulson45 merged commit 29483b0 into main Jul 28, 2021
@dpaulson45 dpaulson45 deleted the lusassl-June21SUWordingFix branch July 28, 2021 16:08
@dpaulson45 dpaulson45 added Enhancement New feature or request Health Checker labels Apr 29, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Enhancement New feature or request Health Checker

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants