Fixing third-party software vulnerabilities
Expand all | Collapse all
After you obtain the software vulnerabilities list, you can fix software vulnerabilities on managed devices that are running Windows. You can fix software vulnerabilities in the operating system and in third-party software, including Microsoft software, by creating and running the Fix vulnerabilities task or the Install required updates and fix vulnerabilities task.
A user interaction may be required when you update a third-party application or fix a vulnerability in a third-party application on a managed device. For example, the user may be prompted to close the third-party application if it's currently open.
As an option, you can create a task to fix software vulnerabilities in the following ways:
- By opening the vulnerability list and specifying which vulnerabilities to fix.
As a result, a new task to fix software vulnerabilities is created. As an option, you can add the selected vulnerabilities to an existing task.
- By running the Vulnerability Fix Wizard.
The Vulnerability Fix Wizard is only available under the Vulnerability and Patch Management license.
The Wizard simplifies creation and configuration of a vulnerability fix task and allows you to eliminate the creation of redundant tasks that contain the same updates to install.
Fixing software vulnerabilities by using the vulnerability list
To fix software vulnerabilities:
- Open one of the lists of vulnerabilities:
- To open the general vulnerability list, go to OPERATIONS → PATCH MANAGEMENT → Software vulnerabilities.
- To open the vulnerability list for a managed device, go to DEVICES → MANAGED DEVICES → <device name> → Advanced → Software vulnerabilities.
- To open the vulnerability list for a specific application, go to OPERATIONS → THIRD-PARTY APPLICATIONS → APPLICATIONS REGISTRY → <application name> → Vulnerabilities.
A page with a list of vulnerabilities in the third-party software is displayed.
- Select one or more vulnerabilities in the list, and then click the Fix vulnerability button.
If a recommended software update to fix one of the selected vulnerabilities is absent, an informative message is displayed.
To fix some software vulnerabilities, you must accept the End User License Agreement (EULA) for installing the software, if EULA acceptance is requested. If you decline the EULA, the software vulnerability is not fixed.
- Select one of the following options:
- New task
The Add Task Wizard starts. If you have the Vulnerability and Patch Management license, the Install required updates and fix vulnerabilities task is preselected. If you do not have the license, the Fix vulnerabilities task is preselected. Follow the steps of the Wizard to complete the task creation.
- Fix vulnerability (add rule to specified task)
Select a task to which you want to add the selected vulnerabilities. If you have the Vulnerability and Patch Management license, select the Install required updates and fix vulnerabilities task. A new rule to fix the selected vulnerabilities will be automatically added to the selected task. If you do not have the license, select the Fix vulnerabilities task. The selected vulnerabilities will be added to the task properties.
The task properties window opens. Click the Save button to save the changes.
If you have chosen to create a task, the task is created and displayed in the task list at DEVICES → TASKS. If you have chosen to add the vulnerabilities to an existing task, the vulnerabilities are saved in the task properties.
To fix the third-party software vulnerabilities, start the Install required updates and fix vulnerabilities task or the Fix vulnerabilities task. If you have created the Fix vulnerabilities task, you must manually specify the software updates to fix the software vulnerabilities listed in the task settings.
Fixing software vulnerabilities by using the Vulnerability Fix Wizard
The Vulnerability Fix Wizard is only available under the Vulnerability and Patch Management license.
To fix software vulnerabilities by using the Vulnerability Fix Wizard:
- On the OPERATIONS tab, in the PATCH MANAGEMENT drop-down list, select Software vulnerabilities.
A page with a list of vulnerabilities in the third-party software installed on managed devices is displayed.
- Select the check box next to the vulnerability that you want to fix.
- Click the Run Vulnerability Fix Wizard button.
The Vulnerability Fix Wizard starts. The Select the vulnerability fix task page displays the list of all existing tasks of the following types:
- Install required updates and fix vulnerabilities
- Install Windows Update updates
- Fix vulnerabilities
You cannot modify the last two types of tasks to install new updates. To install new updates, you can only use the Install required updates and fix vulnerabilities task.
- If you want the Wizard to display only those tasks that fix the vulnerability that you selected, then enable the Show only tasks that fix this vulnerability option.
- Choose what you want to do:
- To start a task, select the check box next to the task name, and then click the Start button.
- To add a new rule to an existing task:
- Select the check box next to the task name, and then click the Add rule button.
- On the page that opens, configure the new rule:
- Rule for fixing vulnerabilities of this severity level
Sometimes software updates may impair the user experience with the software. In such cases, you may decide to install only those updates that are critical for the software operation and to skip other updates.
If this option is enabled, the updates fix only those vulnerabilities for which the severity level set by Kaspersky is equal to or higher than the severity of the selected update (Medium, High, or Critical). Vulnerabilities with a severity level lower than the selected value are not fixed.
If this option is disabled, the updates fix all vulnerabilities regardless of their severity level.
By default, this option is disabled.
- Rule for fixing vulnerabilities by means of updates of the same type as the update defined as recommended for the selected vulnerability (available only for Microsoft software vulnerabilities)
- Rule for fixing vulnerabilities in applications from the selected vendor (available only for third-party software vulnerabilities)
- Rule for fixing a vulnerability in all versions of the selected application (available only for third-party software vulnerabilities)
- Rule for fixing the selected vulnerability
- Approve updates that fix this vulnerability
The selected update will be approved for installation. Enable this option if some applied rules of update installation allow installation of approved updates only.
By default, this option is disabled.
- Click the Add button.
- To create a task:
- Click the New task button.
- On the page that opens, configure the new rule:
- Rule for fixing vulnerabilities of this severity level
Sometimes software updates may impair the user experience with the software. In such cases, you may decide to install only those updates that are critical for the software operation and to skip other updates.
If this option is enabled, the updates fix only those vulnerabilities for which the severity level set by Kaspersky is equal to or higher than the severity of the selected update (Medium, High, or Critical). Vulnerabilities with a severity level lower than the selected value are not fixed.
If this option is disabled, the updates fix all vulnerabilities regardless of their severity level.
By default, this option is disabled.
- Rule for fixing vulnerabilities by means of updates of the same type as the update defined as recommended for the selected vulnerability (available only for Microsoft software vulnerabilities)
- Rule for fixing vulnerabilities in applications from the selected vendor (available only for third-party software vulnerabilities)
- Rule for fixing a vulnerability in all versions of the selected application (available only for third-party software vulnerabilities)
- Rule for fixing the selected vulnerability
- Approve updates that fix this vulnerability
The selected update will be approved for installation. Enable this option if some applied rules of update installation allow installation of approved updates only.
By default, this option is disabled.
- Click the Add button.
If you have chosen to start a task, you can close the Wizard. The task will complete in background mode. No further actions are required.
If you have chosen to add a rule to an existing task, the task properties window opens. The new rule is already added to the task properties. You can view or modify the rule or other task settings. Click the Save button to save the changes.
If you have chosen to create a task, you continue to create the task in the Add Task Wizard. The new rule that you added in the Vulnerability Fix Wizard is displayed in the Add Task Wizard. When you complete the Wizard, the Install required updates and fix vulnerabilities task is added to the task list.
Page top