You have ENS 10.5.1 on Windows 7 64BIT
You have THREAT PREVENTION, Exploit Prevention all HIPS CATEGORY HIGH, MEDUIM, LOW on Report AND Blocking active (All three)
You use Solidcore CAD or any other software that trigger the ExP:Invalid Call in the HIPS Module
This is an in general help from us how to exclude things from the HIPS Module WHICH is integrated in every ENS Endpoint 10.5.X Client from Mcafee.
Alert/Events you see from Mcafee HIPS Module:
Beschreibung / error you see |
Endpoint Security
Ereigniskategorie: Buffer Overflow durch Host-Eindringungsversuch
Schweregrad der Bedrohung: Kritisch
Name der Bedrohung: ExP:Invalid Call
Typ der Bedrohung: Exploit-Schutz
Ausgeführte Aktion: Blockiert
Entdeckungsmethode des Analyseprogramms: Exploit Prevention
Modulname: Bedrohungsschutz
Analyseprogramm – Inhaltsversion: 10.5.0.7691
Analyseprogramm – Regel-ID: 6015
Ziel signiert: Ja
Name des übergeordneten Zielprozesses: SVCHOST.EXE
Zielname: DLLHOST.EXE
Zielpfad: C:\WINDOWS\SYSWOW64
API-Name: OpenProcess
Beschreibung:
ExP:Invalid Call hat einen Exploit-Versuch auf 'C:\WINDOWS\SYSWOW64\DLLHOST.EXE' Blockiert, der vom Modul MWSCRIPTGUI.DLL abgerufen wurde, wodurch ein Angriff auf die API OpenProcess durchgeführt wurde.
|
Here is the Event on the Dashboard
German
English
Notice/Note/Writedown fllwing from the Event above:
- the Analyze RULE ID 6015
- API Name OpenProcess
- Text after Description CALLED MODULE MWSCRIPTGUI.DLL, MWSCRIPTGUI.DLL
Go to your Exploit Policy's:
Now check if the RULE is active reporting and block
Enter the Analyze RULE ID in the Search field and mark all boxes above (Done save, Just to see if you have it active)
Here you see that the RULE 6015 is active in that policy
German
German
English
Now above in the POLICY make an exception from the info we noted from the event above.
This will look like this when done.
German (Screenshot show DL instead of DLL) see English version below
English
SAVE
SAVE (Two times don't forget)
Now TEST and update the Mcafee Agent
ONL if this DOES not work you COULD turn of the rile 6015 complete.
Last (badest) solution option is to turn the HIPS rule 6015 of ENS complete OFF.