<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CVE-2022-30190 in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/cve-2022-30190/m-p/4621780#M6903</link>
    <description>&lt;P&gt;Zero Day Exploit of Microsoft Support Diagnostic Tool Detection. What components of Cisco Secure Endpoint will detect and block this vulnerability?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A title="Guidance for CVE-2022-30190 Microsoft Support Diagnostic Tool Vulnerability" href="https://msrc-blog.microsoft.com/2022/05/30/guidance-for-cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability/" target="_blank" rel="noopener"&gt;https://msrc-blog.microsoft.com/2022/05/30/guidance-for-cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability/&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 31 May 2022 17:55:29 GMT</pubDate>
    <dc:creator>olfuddyduddy</dc:creator>
    <dc:date>2022-05-31T17:55:29Z</dc:date>
    <item>
      <title>CVE-2022-30190</title>
      <link>https://community.cisco.com/t5/endpoint-security/cve-2022-30190/m-p/4621780#M6903</link>
      <description>&lt;P&gt;Zero Day Exploit of Microsoft Support Diagnostic Tool Detection. What components of Cisco Secure Endpoint will detect and block this vulnerability?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A title="Guidance for CVE-2022-30190 Microsoft Support Diagnostic Tool Vulnerability" href="https://msrc-blog.microsoft.com/2022/05/30/guidance-for-cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability/" target="_blank" rel="noopener"&gt;https://msrc-blog.microsoft.com/2022/05/30/guidance-for-cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability/&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 17:55:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cve-2022-30190/m-p/4621780#M6903</guid>
      <dc:creator>olfuddyduddy</dc:creator>
      <dc:date>2022-05-31T17:55:29Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2022-30190</title>
      <link>https://community.cisco.com/t5/endpoint-security/cve-2022-30190/m-p/4622496#M6904</link>
      <description>&lt;P&gt;I believe they are awaiting a signature update from TALOS to help in detection/prevention.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2022 11:56:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cve-2022-30190/m-p/4622496#M6904</guid>
      <dc:creator>Armstnei</dc:creator>
      <dc:date>2022-06-01T11:56:30Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2022-30190</title>
      <link>https://community.cisco.com/t5/endpoint-security/cve-2022-30190/m-p/4622517#M6905</link>
      <description>&lt;P&gt;They added detection this morning.&amp;nbsp; I'm just not sure not sure which engine is picking this and if it will only detect or block/quarantine.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="msdt.png" style="width: 951px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/152543i4365357B5F2D3B69/image-size/large?v=v2&amp;amp;px=999" role="button" title="msdt.png" alt="msdt.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2022 12:25:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cve-2022-30190/m-p/4622517#M6905</guid>
      <dc:creator>sylvain.hamel1</dc:creator>
      <dc:date>2022-06-01T12:25:18Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2022-30190</title>
      <link>https://community.cisco.com/t5/endpoint-security/cve-2022-30190/m-p/4622522#M6906</link>
      <description>&lt;P&gt;Behavioral Protection would need to be enabled.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2022 12:31:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cve-2022-30190/m-p/4622522#M6906</guid>
      <dc:creator>Armstnei</dc:creator>
      <dc:date>2022-06-01T12:31:42Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2022-30190</title>
      <link>https://community.cisco.com/t5/endpoint-security/cve-2022-30190/m-p/4622651#M6907</link>
      <description>&lt;P&gt;How is it known that this is Behavioral Detection and not Exploit Prevention,&amp;nbsp;Exploit Prevention-Script Control, System Process Protection, or Malicious Activity Protection? Is there a place to look to confirm this?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2022 15:36:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cve-2022-30190/m-p/4622651#M6907</guid>
      <dc:creator>olfuddyduddy</dc:creator>
      <dc:date>2022-06-01T15:36:48Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2022-30190</title>
      <link>https://community.cisco.com/t5/endpoint-security/cve-2022-30190/m-p/4623586#M6909</link>
      <description>&lt;P&gt;Hello S.H.,&lt;/P&gt;&lt;P&gt;Thank you for posting this.&amp;nbsp; If you don't mind sharing a little more, where is this information from?&amp;nbsp; How do I find this information source for future reference?&amp;nbsp; Thank you for any assistance you can provide.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-&amp;nbsp; CB&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jun 2022 20:40:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cve-2022-30190/m-p/4623586#M6909</guid>
      <dc:creator>crockbot</dc:creator>
      <dc:date>2022-06-02T20:40:41Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2022-30190</title>
      <link>https://community.cisco.com/t5/endpoint-security/cve-2022-30190/m-p/4623595#M6910</link>
      <description>&lt;P&gt;I found it in the Indicators page (&lt;A href="https://console.amp.cisco.com/indicators" target="_blank"&gt;Indicators (cisco.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In Analysis--&amp;gt;Indicators of the console.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="msdt2.jpg" style="width: 426px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/152671iD05A1374B358F9DE/image-size/large?v=v2&amp;amp;px=999" role="button" title="msdt2.jpg" alt="msdt2.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jun 2022 21:25:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cve-2022-30190/m-p/4623595#M6910</guid>
      <dc:creator>sylvain.hamel1</dc:creator>
      <dc:date>2022-06-02T21:25:40Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2022-30190</title>
      <link>https://community.cisco.com/t5/endpoint-security/cve-2022-30190/m-p/4623596#M6911</link>
      <description>&lt;P&gt;Just sad that they don't have a published/modified date that we could filter on (so that you can see new Indicators added easily....).&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jun 2022 21:27:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cve-2022-30190/m-p/4623596#M6911</guid>
      <dc:creator>sylvain.hamel1</dc:creator>
      <dc:date>2022-06-02T21:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: CVE-2022-30190</title>
      <link>https://community.cisco.com/t5/endpoint-security/cve-2022-30190/m-p/4623604#M6912</link>
      <description>&lt;P&gt;Thank you Sylvain. I was able to find the same indicator using general search on "msdt". I'm still trying to determine which AMP detection engine is necessary to be certain this is detecting in my enterprise. The indicator doesn't have that information listed on the indicator blurb. Any clues as to how you determined behavioral engine to be the engine necessory to make use of this indicator?&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jun 2022 21:44:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cve-2022-30190/m-p/4623604#M6912</guid>
      <dc:creator>olfuddyduddy</dc:creator>
      <dc:date>2022-06-02T21:44:11Z</dc:date>
    </item>
  </channel>
</rss>

