Update microsoft-recommended-block-rules.md

BGInfo has moved on from version 4.22 and references to it as being "the latest version" was misleading.
This commit is contained in:
Anders Ahl 2022-09-14 16:08:12 +02:00 committed by GitHub
parent 079fd2900e
commit 4c0868fbb4
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -75,7 +75,7 @@ Unless your use scenarios explicitly require them, Microsoft recommends that you
- wslconfig.exe - wslconfig.exe
- wslhost.exe - wslhost.exe
<sup>1</sup> A vulnerability in bginfo.exe has been fixed in the latest version 4.22. If you use BGInfo, for security, make sure to download and run the latest version here [BGInfo 4.22](/sysinternals/downloads/bginfo). BGInfo versions earlier than 4.22 are still vulnerable and should be blocked. <sup>1</sup> A vulnerability in bginfo.exe has been fixed in version 4.22. If you use BGInfo, for security, make sure to download and run the latest version here [BGInfo](/sysinternals/downloads/bginfo). BGInfo versions earlier than 4.22 are still vulnerable and should be blocked.
<sup>2</sup> If you're using your reference system in a development context and use msbuild.exe to build managed applications, we recommend that you allow msbuild.exe in your code integrity policies. However, if your reference system is an end-user device that isn't being used in a development context, we recommend that you block msbuild.exe. <sup>2</sup> If you're using your reference system in a development context and use msbuild.exe to build managed applications, we recommend that you allow msbuild.exe in your code integrity policies. However, if your reference system is an end-user device that isn't being used in a development context, we recommend that you block msbuild.exe.