CVE Policies Page
To help control user access to programs related to a CVE, PC Matic has added a CVE Policies page in the portal. This page is located under Account Settings and the link is in the Security section. With this feature, administrators can create policies to choose to be alerted to programs affected by a CVE being allowed to run in the environment, allow those programs to be run, or block those programs from running.

To create a CVE policy, click on the CVE policy button located in the right hand corner. Administrators will be given different options to create a policy as shown below.

For policy conditions, administrators can choose to be just alerted or be alerted and allow or block the program(s) covered by a CVE that matches the other criteria in the policy. In this section, administrators can also choose to mandate whether an exploit or patch is present or not present before the policy applies.
For severities, administrators can choose one or multiple severities. The severity of the CVE that triggers a policy will appear in the notification alert.
Administrators can further choose to specify specific software vendors, software products, and CVE ids to be affected by a CVE policy. Policy assignments can be designated for companies, groups, or individual computers. Multiple assignments can be selected or present in one policy.
If a program is clicked on and is affected by an alert or block CVE policy, a notification will appear in the portal with additional information on the CVE involved including a link to the information available from NIST, the file hash and path of the program, policy level that was triggered, and, where available, actions that the administrator can take (such as links to a patch). If a CVE policy calls for a program to be blocked, that behavior will also occur along with the notification.

For an alert only CVE policy, there will be no popup or other message on a user’s device, only a notification in the portal. If the policy specifies allow, the program is allowed to run on a user’s device and just like with an alert, the user will see no popup. For a policy that specifies block, the program will be blocked from running and the user will see a standard block popup.
If a program/process matches 2 or more CVE policies, policies are prioritized in this order:
-
contains a CVE ID filter
-
contains a product filter
-
contains a vendor filter
-
contains a severity filter
Why might an administrator want to use CVE policies? Suppose that a new zero-day vulnerability is discovered in a program used in your organization and it doesn’t currently have a patch. With a CVE policy specifying that distinct program or CVE id, an organization could be alerted and have the vulnerable program blocked from running. This will save an administrator from having to uninstall the program from all their devices and still chance missing an instance of the vulnerable program or even having the vulnerable program started by another program. When a patch is available, that can also appear in a CVE notification alert.
Another example is if your organization uses a vulnerable program that you don’t want to block due to its’ importance (such as a database program or accounting software), but an administrator does want to be alerted when it is run, when there is an active exploit, or when a patch is available.