GFI Software

Welcome to the GFI Software community forum! For support please open a ticket from https://support.gfi.com.

Home » GFI User Forums » GFI LanGuard » CVE-2020-0744 and CVE-2019-0765 (Flase Alarm)
CVE-2020-0744 and CVE-2019-0765 [message #147760] Wed, 18 March 2020 04:53 Go to next message
erictsang is currently offline  erictsang
Messages: 4
Registered: March 2020
Hi,

I have 2 issues that looking for help.

1. CVE-2020-0744
I have patch installed for this but after full scan languard still prompts me as low risk, is there a bug again?

2. CVE-2019-0765
I submitted a request to support, they provided me a way to ignore this in rule manager, I have done it.
But when I generate a vscan report, it still show me this vulnerability as high risk. I need a clean report
for Audit, may I know how can I ignore this in vscan report?
Re: CVE-2020-0744 and CVE-2019-0765 [message #147766 is a reply to message #147760] Wed, 18 March 2020 15:57 Go to previous messageGo to next message
rsbomar is currently offline  rsbomar
Messages: 12
Registered: March 2020
Have you checked your devices to see what version of comctl32.dll you have installed. Check the date/time and version of the file and post it here. I have the same problem but I suspect it is a problem with Microsoft Updates. My comctl32.dll is dated 9/15/2018 and has a file version of 5.82.1776.1131 and a product version of 10.0.17763.1131.
Re: CVE-2020-0744 and CVE-2019-0765 [message #147774 is a reply to message #147766] Thu, 19 March 2020 02:36 Go to previous messageGo to next message
erictsang is currently offline  erictsang
Messages: 4
Registered: March 2020
My comctl32.dll is dated 8/23/2018 and has a file version of 5.82.14393.2457 and a product version of 10.0.14393.2457.
The file is located in c:\Windows\System32
Re: CVE-2020-0744 and CVE-2019-0765 [message #147793 is a reply to message #147774] Fri, 20 March 2020 17:40 Go to previous messageGo to next message
rsbomar is currently offline  rsbomar
Messages: 12
Registered: March 2020
What OS is your device?
Re: CVE-2020-0744 and CVE-2019-0765 [message #147833 is a reply to message #147793] Wed, 25 March 2020 18:58 Go to previous messageGo to next message
rsbomar is currently offline  rsbomar
Messages: 12
Registered: March 2020
Can someone from GFI please chime in here? What good is this "Moderated Forum" if you guys can't answer paying customers questions?
Re: CVE-2020-0744 and CVE-2019-0765 [message #147840 is a reply to message #147833] Thu, 26 March 2020 09:00 Go to previous messageGo to next message
erictsang is currently offline  erictsang
Messages: 4
Registered: March 2020
Thanks rsbomar, my OS is Server 2016, I do patching on servers every month after MS release their patch. So I am actually doing a trial on this product and I am disappointed .....
Re: CVE-2020-0744 and CVE-2019-0765 [message #147875 is a reply to message #147840] Fri, 27 March 2020 20:51 Go to previous messageGo to next message
rsbomar is currently offline  rsbomar
Messages: 12
Registered: March 2020
My 2016 servers are also showing the CVE-2020-0744 vulnerability event though the servers are fully patched.
Re: CVE-2020-0744 and CVE-2019-0765 [message #147876 is a reply to message #147840] Fri, 27 March 2020 20:55 Go to previous messageGo to next message
rsbomar is currently offline  rsbomar
Messages: 12
Registered: March 2020
Can someone from GFI please inform us what causes CVE-2020-0744 to fail? If you look at the information on that CVV it points to Microsoft support site that shows the security patch KB4537764 fixes this issue. Well my server has KB4537764 installed but my server still reports this vulnerability.
Re: CVE-2020-0744 and CVE-2019-0765 [message #147877 is a reply to message #147876] Sat, 28 March 2020 02:59 Go to previous message
erictsang is currently offline  erictsang
Messages: 4
Registered: March 2020
This is very annoying as if I rely on the vscan report for passing the security audit....
Previous Topic: Latitude & Longitude Settings
Next Topic: Security Vulnerability
Goto Forum:
  


Current Time: Fri Sep 29 12:04:58 CEST 2023

Total time taken to generate the page: 0.07024 seconds