Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Windows build number not detected properly #23275

Closed
andonovski opened this issue May 5, 2024 · 3 comments
Closed

Windows build number not detected properly #23275

andonovski opened this issue May 5, 2024 · 3 comments
Assignees

Comments

@andonovski
Copy link

andonovski commented May 5, 2024

Wazuh version Component Install type Install method Platform
4.7.4 Vulnerability scanner Manager Docker Ubuntu 22.04

Wazuh version 4.74 is installed using docker on Ubuntu server 22.04 LTS.
The issue is in Vulnerabilities for Windows Server 2022 22H2, build is 20348. Selecting any Windows Server 2022 22H2 shows CVE-2023-36046. Link for this CVE is https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36046, further going to KB link https://support.microsoft.com/en-us/topic/november-14-2023-kb5032202-os-build-25398-531-e1ee8019-47f8-4314-be67-32d4e48ac140.

As it can be seen, this CVE is only for Windows Server 2022 23H2, not for 22H2.

Now, my question is, is this a bug not properly detecting Windows build? Or is it just working this way, not detecting build number at all? Maybe something is wrong with my Wazuh configuration?

@pereyra-m
Copy link
Member

Hello @andonovski !

It happens that the NVD isn't specific about the Windows Server 2022 version affected

https://nvd.nist.gov/vuln/detail/CVE-2023-36046
2024-05-06_10-01

So the scanner considers that unless KB5032202 (or any equivalent update) is installed, all Windows Server 2022 systems are vulnerable. The Wazuh agent collects properly the 22H2 version field but the vulnerability content has to be fixed.

Soon, the new Wazuh v4.8.0 will be released (see issue #14156) and the vulnerability detector module will be able to handle this type of situations

@andonovski
Copy link
Author

andonovski commented May 6, 2024 via email

@pereyra-m
Copy link
Member

Thanks to you!
The reports from the community help to improve Wazuh.

Regards.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants