Wegweiser
All notes

Software its vendor no longer fixes

The Security briefing has a new chapter: every version on your clients' machines that its vendor has stopped fixing, or will stop fixing within six months. It also reads browser versions against the vendor's fixed release, so a flaw every machine already has the fix for stops being news. And every check on a device page now ends on what to do.

Until now the Security briefing answered one question: which of the flaws attackers are exploiting this week reach your clients' machines. It said nothing about the Office 2016 that stopped getting fixes last October. Yet that is the finding that turns into a project. A flaw in a supported product has a fix, and the same flaw in a retired version never will.

So the briefing now asks a second question, in a chapter of its own called Unsupported software: which machines run something its vendor no longer fixes, or will stop fixing within six months?

What it looks for

It covers:

  • Office, 2007 to 2021;
  • SQL Server, 2008 to 2017;
  • Exchange and SharePoint, 2010 to 2019;
  • Silverlight and Flash Player.

Each version is found by the names its editions install under, never by a fragment of one. Each date comes from the vendor's own lifecycle page, and every card links to that page.

Operating systems use the same end-of-support dates the device page already shows, for Windows, Windows Server and the major Linux distributions.

What a card says

Each card names:

  • the machines and the clients they belong to;
  • when support ended, or when it ends;
  • how many actively exploited flaws CISA lists for the product as a whole. That last one is a fair measure of how much the missing fixes are likely to matter.

The colour tells you how urgent it is:

  • Red: support has ended and nothing comes after it.
  • Amber: standard support has ended but an extended track is still running, as with Windows 10's paid security updates or Debian's long-term support. The card gives the date the extended track ends. An agent cannot see whether a machine is actually enrolled, so the card says "where it is in place" rather than guessing.
  • Amber: support ends within six months. The card counts the days left, so the replacement can be planned before the day rather than after it.

On its first read the chapter found:

  • Office 2007, SQL Server 2014 and Silverlight, all long past support and still installed;
  • an Office 2021 whose support ends on 13 October.

Where else it shows

These rows appear on:

  • the tenant overview and each client's page, after the exploited ones;
  • the Monday email;
  • the chat, so "which of this client's machines still run Office 2016?" gets the same answer as the page.

A client with nothing exploited this month but an unsupported version on one machine no longer looks like a client with nothing to see.

A browser that already has the fix

Until now the briefing said only where software is installed. "Chrome installed on 19 machines" was mostly about machines that had updated themselves before CISA listed the flaw, and nothing on the card told those apart from the one that had not.

For Chrome, Chromium and Edge, the briefing now reads each machine's version against the first release the vendor fixed the flaw in:

  • Google publishes that release in the CVE record it writes for Chrome;
  • Microsoft publishes it for Edge in its Security Update Guide.

A card now says, for example, "1 of 7 runs a version older than Microsoft's fixed release", and marks each version seen: older ones in red, fixed ones in green.

A flaw that every machine already has the fix for moves to a chapter of its own, Already fixed. It leaves the overview and the counts, and it sends no alert. If a machine on an older version turns up while the flaw is still news, the alert goes out then.

The card says "older", not "vulnerable". A company on Chrome's extended-stable channel gets the fix under an older version number, and Google's record names only the stable release. Brave, Opera and Vivaldi publish nothing that can be compared this way. Their versions are still shown for you to check, and a card that lists them next to Chrome says so.

On the first read:

  • every Chrome but one was already fixed;
  • one Edge was still on version 151;
  • for two of the MSPs using Wegweiser, every machine already had both fixes.

Every check ends on what to do

Every analysis on a device page now follows the same order:

  1. the verdict;
  2. what the check saw;
  3. a closing paragraph that begins "Recommended action:".

Before this, only a third of analyses ended on anything the page could recognise as a next step. Many closed on a second justification of their score instead, because their own instructions asked for it last.

Commands, file paths, services, packages and event IDs are now set as code, so apt upgrade or Kernel-Power 41 reads as something you type or search for, not as part of the sentence.

An agent too old to update itself

Agents keep themselves up to date, but only from version 0.3.68, the first with the updater. Agents installed before that cannot update, and until now they stayed silently on whatever version they were installed with. They are now named in two places:

  • the Agent Updates page under Settings lists them by machine;
  • each one's device page says it in plain words: this agent will never update itself, so install the current one on that machine by hand.

More notes

  1. VirusTotal, on your own key

  2. Website security with nothing to set up

  3. What is being exploited, and where it reaches