GlobalProtect client failing HIP Check even though the Microsoft patch is installed

GlobalProtect client failing HIP Check even though the Microsoft patch is installed

4238
Created On 08/03/23 04:06 AM - Last Modified 10/25/24 20:52 PM


Symptom


  • In GlobalProtect logs (PanGPA.log), Microsoft patch is listed in "missing-patches" section of the Hip report:
<hip-report name="hip-report">
....
                <missing-patches>
                    <entry>
                        <title>Security Intelligence Update for Microsoft Defender Antivirus - KB2267602 (Version 1.325.782.0)</title>  
                        <description>Install this update to revise the files that are used to detect viruses, spyware, and other potentially
unwanted software. Once you have installed this item, it cannot be removed.</description>                         <product>Microsoft Defender Antivirus</product>                         <vendor>Microsoft Corporation</vendor>                         <info-url/>                         <kb-article-id>2267602</kb-article-id>                         <security-bulletin-id/>                         <severity>2</severity>                         <category>definition_update</category>                         <is-installed>no</is-installed>                     </entry>

 



Environment


  • Palo Alto Firewalls
  • Supported PAN-OS
  • GlobalProtect App on Windows
  • Microsoft Patch updates


Cause


Issue is due to Microsoft Internal APIs which are in turn used by Opswat integrated by GlobalProtect.



Resolution


  1. Check with Microsoft Support to help fix the issue. OR
  2. Exempt specific security patches from being reported as missing from the endpoint HIP report to prevent the endpoint from failing the HIP check.

Note: This feature is available starting from GP 6.2 version. Refer Host Information Profile exceptions for Patch Management.



    Actions
    • Print
    • Copy Link

      https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000XfwPCAS&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

    Choose Language