PingCastle Patch Version 3.5.1.33 Released

Want the full details? Click the link below!

Bug Fixes and Miscellaneous Updates

What’s New — Bug Fixes

Escalation Fix

PingCastle Pro — Unable to Access Website After Upgrade (HTTP 400 Error)
Escalation #439100

PingCastle Pro now applies the same secure cookie authentication configuration as PingCastle Enterprise. Session cookies are marked HttpOnly, use a server-side ticket store, and respect a configurable expiry (defaulting to 2 days) with sliding expiration enabled. This brings authentication session behaviour in Pro into parity with Enterprise and closes a gap in session-security hardening.


GitHub Reported Issues — HotFix Scanner

PingCastle.exe Detected by Windows Defender
GitHub Issue #354

A recent release added a CIM collector option to the HotFix scanners (for MS14-068 and MS17-010) to improve collection speeds. This improvement inadvertently triggered Windows Defender antivirus definitions.

The CIM collection option has been removed. This will be revisited after the 4.0 release to deliver a working CIM collector that does not trigger antivirus definitions.

Original community idea: Optimize WMI Queries to Be Modern and Faster


False Positives for MS17-010
GitHub Issue #333

Certain operating systems were still producing false positives in the HotFix scanner for MS17-010. Two issues have been resolved:

  • The fallback mechanism was not being invoked in certain circumstances.
  • The KB HotFix lists were incomplete for some operating systems.

Need help with this update?

There are many different ways to get help with our products!

Situation Action
If you feel the product is broken and not working as intended… Contact Support
If you have a question you’d like to ask other experts… Create a discussion in the community: PingCastle > Discussions & Questions
If you have a feature request… Let our product team know directly: PingCastle > Ideas
If you have something cool to show… Show everyone what you built: PingCastle > Show & Tell

What are your thoughts?

We are always happy to hear from our users on what you like, and what you hope to see in the future. Please, share your thoughts below!

PingCastle 3.5.1.33 is still detected by Windows Defender as malware.
It detects it as Trojan:Script/Wacatac.C!ml and Trojan:Win32/Tecabans.STV!cl

Interesting, we didn’t have this on release and got confirmation from another community member too. We will investigate

Just an update: The File is still detected as malware by Windows Defender. I submitted the archive to Microsoft WDSI for malware analysis some days ago. But seems they have not yet recategorized the file.

2 Likes

Any news here? The file is still triggers Alert: “‘Tecabans’ malware was prevented”

Update: The virus warning only appears for the release available on github
It does NOT appear for the download from the netwrix support portal.