Link to home
Start Free TrialLog in
Avatar of nav2567
nav2567Flag for United States of America

asked on

Qualys report for windows servers.

Hello,

I am reading this Qualys vulnerability report which says a server has this IE vulnerability - Please see the attached.  The server already has latest Windows Updates.  

I have apply latest Windows updates to the server.  There are three links under the Expolitability session in the report which the download link to fix the vulnerability is supposed to be available.  But it happens that the download link only downloads a txt file.  

Someone who has an idea please advise.  

Many thanks.
qualys-report.docx
Avatar of Ibrahim Benna
Ibrahim Benna
Flag of Canada image

If you scroll to the bottom of the link or even in the text file downloaded, you'll see a link to a zip file from github.com

E.G.: https://github.com/offensive-security/exploitdb-bin-sploits/raw/master/bin-sploits/46022.zip
Avatar of nav2567

ASKER

I do not see any github.com link at all in the attached file I sent.
interesting - well the workaround is to go directly to www.exploit-db.com and do a search for the reference values (Reference: CVE-2018-8625) using the CVE number. that's how I got to the GitHub.com site
Avatar of nav2567

ASKER

I see that.  The downloaded file is 46022.txt which I stated in my original question.  I am not sure of what action to take.
This question needs an answer!
Become an EE member today
7 DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform.
View membership options
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.