Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

DisplayLink.Graphics update sets off Antivirus #4476

Open
poa00 opened this issue May 13, 2024 · 2 comments
Open

DisplayLink.Graphics update sets off Antivirus #4476

poa00 opened this issue May 13, 2024 · 2 comments
Labels
Issue-Bug It either shouldn't be doing this or needs an investigation.

Comments

@poa00
Copy link

poa00 commented May 13, 2024

Brief description of your issue

When I used winget to upgrade the DisplayLinks Graphics on my enterprise machine, antivirus flags it with "Vulnerability detected." Unfortunately, in my scramble to delete the downloaded files, I did not screenshot the warning.

Steps to reproduce

Run winget upgrade -Name <name of DisplayLink Graphics update>

Expected behavior

Update proceeds normally.

Actual behavior

Update blocked by Enterprise Security.

Environment

Windows Package Manager v1.7.11261
Copyright (c) Microsoft Corporation. All rights reserved.

Windows: Windows.Desktop v10.0.22621.3447
System Architecture: X64
Package: Microsoft.DesktopAppInstaller v1.22.11261.0

Winget Directories
-----------------------------------------------------------------------------------------------------------------------
Logs                               %LOCALAPPDATA%\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\Diag…
User Settings                      %LOCALAPPDATA%\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\LocalState\sett…
Portable Links Directory (User)    %LOCALAPPDATA%\Microsoft\WinGet\Links
Portable Links Directory (Machine) C:\Program Files\WinGet\Links
Portable Package Root (User)       %LOCALAPPDATA%\Microsoft\WinGet\Packages
Portable Package Root              C:\Program Files\WinGet\Packages
Portable Package Root (x86)        C:\Program Files (x86)\WinGet\Packages
Installer Downloads                %USERPROFILE%\Downloads

Links
---------------------------------------------------------------------------
Privacy Statement   https://aka.ms/winget-privacy
License Agreement   https://aka.ms/winget-license
Third Party Notices https://aka.ms/winget-3rdPartyNotice
Homepage            https://aka.ms/winget
Windows Store Terms https://www.microsoft.com/en-us/storedocs/terms-of-sale

Admin Setting                             State
--------------------------------------------------
LocalManifestFiles                        Disabled
BypassCertificatePinningForMicrosoftStore Disabled
InstallerHashOverride                     Disabled
LocalArchiveMalwareScanOverride           Disabled
@microsoft-github-policy-service microsoft-github-policy-service bot added the Needs-Triage Issue need to be triaged label May 13, 2024
@Trenly
Copy link
Contributor

Trenly commented May 13, 2024

Can you please share the list of security software on your device? I've tried running this on my VM with several different Antivirus Softwares and none of them have triggered. I also checked the file and the download URL with VirusTotal and both showed 0 flags.

Based on the message Blocked by Enterprise Security, it seems likely that your Enterprise security rules might not be updated, might have an explicit block, or are just extremely strict, as I'm not able to replicate this issue at all

@microsoft-github-policy-service microsoft-github-policy-service bot removed the Needs-Triage Issue need to be triaged label May 13, 2024
@poa00
Copy link
Author

poa00 commented May 13, 2024

Yes I work for a global tech consulting firm that boasts having the world's best security services so I would not be surprised if they are understandably protecting their good name from the likes of me and my casual browsing 😆 To answer your question though (which maybe I just did) all of the security software (aside from Defender) is developed in-house specifically for internal workstations and not publicly available / known.

Edit: (If it helps) the file that was flagged was one created in the %LocalAppData% directory in a subfolder namedDL2.tmp. Unfortunately I did not catch the filename but it was identified as a 7Z SFX Console file, presumably a self-extracting archive.

@denelon denelon added the Issue-Bug It either shouldn't be doing this or needs an investigation. label May 14, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Issue-Bug It either shouldn't be doing this or needs an investigation.
Projects
None yet
Development

No branches or pull requests

3 participants