BigFix has X number of KB Fixlets relevant & Qualys states 6 times that?

If in fact the issue is due to supersedence (which is certainly possible, and relatively easy to confirm), an alternative approach to modifying the relevance is to have the BigFix Client evaluate newer superseded patches by modifying a Client setting (_BESClient_WindowsOS_EnableSupersededEval=1).

Please see Pre-Announcement: Superseded patch changes for Patches for Windows for more information.

Of course, if this is the case, and you apply the most recent patches that show as applicable via BigFix, it should drop the number of applicable patches in the vulnerability management scanner quite significantly.

1 Like