This guide applies to Mac and Windows computers
About Vulnerability Response
Vulnerability Response enables you to automate the handling of security vulnerabilities (Common Vulnerabilities and Exposures, or CVEs) for macOS and Windows apps that exist in the Auto App catalog. You can set up rules that tell Iru Endpoint how to respond based on the severity of each CVE; when Iru Endpoint identifies an app with a known vulnerability, it can automatically update that app according to the rules you’ve put in place. You set those rules once. After that, matching CVEs are handled on check-in rather than as a one-off update each time a disclosure lands.How It Works
Vulnerability Response scans and remediates all installed applications that match an item in the Auto App catalog, by bundle ID on macOS and by app name and publisher on Windows, even if the Auto App Library Item is not currently in your Library or assigned to a Blueprint. If an app is affected by multiple vulnerabilities with different severities, Vulnerability Response will perform the selected remediation action only for the highest applicable severity. On each Iru Agent check-in, Vulnerability Response compares the applications installed on your Mac and Windows fleet against existing CVEs in the National Vulnerability Database (NVD). If a match is found between a CVE and an installed app, Vulnerability Response will flag that match and perform the selected Remediation Action against the app to mitigate the vulnerability, if a matching Auto App is found in the catalog. Once you’ve configured the Vulnerability Response Library Item, it monitors devices for known vulnerabilities. On each Iru Agent check-in, it compares installed applications against the CVE database by bundle ID on macOS and by app name and publisher on Windows in the Auto App catalog. When a match is found, it applies your Remediation Action for the highest applicable severity. Vulnerabilities in apps not supported as Auto Apps must be updated directly by the app developer. Requests for additional Auto App support can be submitted through the Iru Endpoint Web App using the Feature Requests button.Remediating Vulnerabilities
Available Remediation Actions
In Remediation options, choose a Remediation action for each CVE severity:- Critical severity (CVSS 9-10)
- High severity (CVSS 7-8.9)
- Medium severity (CVSS 4-6.9)
- Low severity (CVSS 0.1-3.9)
When a vulnerability is found, Iru Endpoint immediately updates the affected app to the latest version. Enforce update on a timeframe
When you choose a timeframe, Iru Endpoint will update the app based on the selected enforcement timeframe. No Action
If a vulnerability at this severity level is found, Iru Endpoint won’t take any action.
The Iru Agent respects the user’s local time zone for update enforcement.
Viewing Remediated CVEs
When all affected software and devices associated with a CVE are patched, the CVE is assigned a Remediated status.1
Navigate to Vulnerability Management
Navigate to the Vulnerability Management tab.
2
Filter for Remediated CVEs
Use the Status filter and select Remediated.
CVE Detail View
Selecting a specific CVE opens its detail view, where you can monitor progress and review device status related to that vulnerability. On the Overview tab, the Impacted devices section shows the percentage of devices remediated, along with remediated and active device counts for the selected CVE. Use the Timeline tab to track the history of the CVE, including when it was published, modified, and detected in your environment.Setting Up the Vulnerability Response Library Item
To add this Library Item to your Iru Endpoint Library, follow the steps outlined in the Library Overview article. Under Install on, select Apple, Windows, or both. The Exceptions section has separate macOS exceptions and Windows exceptions cards.1
Name the Library Item
Give the Vulnerability Response Library Item a name.
2
Choose platforms
Under Install on, select Apple, Windows, or both.
3
Assign to Blueprints
Under Assignment Maps, select + Assign to assign the Library Item to one or more Blueprints.
4
Configure Remediation options
In Remediation options, select the Remediation action for each severity: Critical, High, Medium, and Low.
5
Add exceptions (optional)
In Exceptions, configure macOS exceptions and Windows exceptions separately. Select Add application in the section for each platform you selected. Each list shows App Name. macOS exceptions also show Bundle ID. Windows exceptions also show Publisher. If a vulnerability is detected on an excluded application, Vulnerability Response will take no action.
6
Save Configuration
Select Save.
User Experience with Vulnerability Response
Updates are delivered silently to the end user, following the same workflow as Auto Apps. When an enforcement deadline is reached and the affected app is open, users will see a prompt with a 5-minute countdown to close the application and save work. If the app isn’t closed, it will be forcibly closed and updated. On Mac computers, the app will reopen after updating.Considerations
App Support Requirements- Only app-based vulnerabilities are remediated, and only when Iru Endpoint provides a supported Auto App for the application
- Vulnerability Response can update supported apps even if you aren’t also using the Auto App Library Item for that app
- Deployment occurs via the Iru Agent, which is pre-installed on all enrolled Mac and Windows computers
- No additional installation or configuration is needed; simply assign the Vulnerability Response Library Item to your Blueprints
- Vulnerability Response updates vulnerable apps; it doesn’t block them at launch
- The App Blocking Library Item can be used to block apps if required
- If both an Auto App and a Vulnerability Response Library Item are targeting the same application, Vulnerability Response will update the app if the vulnerability is detected before the Auto App enforcement deadline
- If a device is assigned both Vulnerability Response and Auto App Library Items with different enforcement deadlines for the same app, the earliest enforcement deadline will apply
- On Mac computers, Vulnerability Response takes priority over phased rollout when an update must be enforced sooner
- Multiple Vulnerability Response Library Items can be configured within a Blueprint for different groups, but only one may be assigned per device
- If a device qualifies for more than one, the last (furthest right in the Assignment Map) is applied
- If a CVE previously marked as “Risk Accepted” is patched, its status will change to “Remediated”
- If the vulnerability is detected again and the policy isn’t updated, its status will revert to “Risk Accepted”