{"id":208090,"date":"2023-07-24T07:40:29","date_gmt":"2023-07-24T07:40:29","guid":{"rendered":"https:\/\/www.ninjaone.com\/script-hub\/come-ridurre-i-rischi-legati-a-cve-2023-36884-con-powershell\/"},"modified":"2024-03-04T16:06:41","modified_gmt":"2024-03-04T16:06:41","slug":"come-ridurre-i-rischi-legati-a-cve-2023-36884-con-powershell","status":"publish","type":"script_hub","link":"https:\/\/www.ninjaone.com\/it\/script-hub\/come-ridurre-i-rischi-legati-a-cve-2023-36884-con-powershell\/","title":{"rendered":"Microsoft 0-Day senza patch: Come ridurre il rischio legato a CVE-2023-36884 con PowerShell"},"content":{"rendered":"<p>Gli aggiornamenti del Patch Tuesday di luglio 2023 di Microsoft hanno evidenziato diverse vulnerabilit\u00e0 sfruttate attivamente, tra cui una (o pi\u00f9?) ancora senza una patch risolutiva. Ecco cosa hai bisogno di sapere su\u00a0<a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2023-36884\" target=\"_blank\" rel=\"noopener\">CVE-2023-36884<\/a>, una vulnerabilit\u00e0 zero-day che gli aggressori stanno sfruttando per eseguire codice da remoto tramite documenti Microsoft Office &#8220;appositamente creati&#8221;.<\/p>\n<h2>Che cos&#8217;\u00e8 CVE-2023-36884?<\/h2>\n<p>Risposta breve: <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2023-36884\" target=\"_blank\" rel=\"noopener\">Microsoft definisce CVE-2023-36884<\/a> come una vulnerabilit\u00e0 che permette di eseguire codice da remoto tramite Office e Windows HTML, con un punteggio CVSS di base pari a 8,3. Risposta pi\u00f9 significativa: Cosa succeder\u00e0? Per il momento, le dichiarazioni della societ\u00e0 sembrano suggerire che Microsoft stia ancora indagando attivamente sulla situazione, e non forniscono molte informazioni al di l\u00e0 di una descrizione sommaria. L&#8217;azienda afferma che uno sfruttamento riuscito della vulnerabilit\u00e0 pu\u00f2 consentire a un aggressore di eseguire codice da remoto nell\u2019ambiente IT di chi subisce l&#8217;attacco, e per farlo \u00e8 necessario semplicemente ingannare la vittima spingendola ad aprire un documento Microsoft Office appositamente creato. La dichiarazione di Microsoft si apre in modo curioso affermando: &#8220;Microsoft sta indagando sulle segnalazioni di una <strong>serie\u00a0<\/strong> di vulnerabilit\u00e0 relative all\u2019esecuzione di codice da remoto&#8221; (l\u2019enfasi posta sulle parole in grassetto \u00e8 mia), e quanto scoperto fino a ora induce l&#8217; <a href=\"https:\/\/twitter.com\/wdormann\/status\/1678922526905233408?s=20\" target=\"_blank\" rel=\"noopener\">esperto di vulnerabilit\u00e0 Will Dormann a ipotizzare quanto segue<\/a>: &#8220;CVE-2023-36884 \u00e8 semplicemente un placeholder per un aggiornamento che riguarder\u00e0 pi\u00f9 vulnerabilit\u00e0 in un singolo CVE, e che potrebbe essere rilasciato in un futuro pi\u00f9 o meno prossimo.&#8221; Sebbene la dichiarazione in s\u00e9 manchi di dettagli, rimanda a <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2023\/07\/11\/storm-0978-attacks-reveal-financial-and-espionage-motives\/\" target=\"_blank\" rel=\"noopener\">un post sul blog<\/a> che fa luce sul modo in cui Microsoft ha scoperto la vulnerabilit\u00e0.<\/p>\n<h2>Spionaggio e ransomware &#8211; sfruttamento attivo di CVE-2023-36884<\/h2>\n<p>A giugno, <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2023\/07\/11\/storm-0978-attacks-reveal-financial-and-espionage-motives\/\" target=\"_blank\" rel=\"noopener\">Microsoft ha individuato<\/a> una campagna di phishing lanciata da un criminale informatico che Microsoft identifica con il nome di Storm-0978. La campagna ha preso di mira enti governativi e della difesa in Nord America e in Europa, con esche legate al Congresso mondiale ucraino. Le e-mail inviate nell&#8217;ambito della campagna contenevano link a documenti Word che sfruttavano CVE-2023-36884 per installare backdoor. Sebbene questi obiettivi e le attivit\u00e0 successive alla compromissione suggeriscano motivazioni di spionaggio, Microsoft dichiara di aver scoperto che, mentre questa campagna era in corso, Storm-0978 conduceva attacchi ransomware separati, su obiettivi non correlati, utilizzando gli stessi payload iniziali. Secondo Microsoft, l&#8217;attivit\u00e0 di ransomware dell&#8217;aggressore \u00e8 stata &#8220;in gran parte di natura opportunistica e completamente separata dagli obiettivi di spionaggio&#8221; AGGIORNAMENTO: Un&#8217;ancora pi\u00f9 <a href=\"https:\/\/blogs.blackberry.com\/en\/2023\/07\/romcom-targets-ukraine-nato-membership-talks-at-nato-summit\" target=\"_blank\" rel=\"noopener\">approfondita analisi tecnica di questa campagna<\/a> \u00e8 disponibile presso BlackBerry.<\/p>\n<h2>\u00c8 disponibile una patch per CVE-2023-36884?<\/h2>\n<p>Al momento, no. Microsoft ha fatto sapere di stare ancora indagando attivamente su questa vulnerabilit\u00e0 e ha rilasciato la seguente dichiarazione in merito alle azioni che seguiranno: \u201cAdotteremo le misure appropriate per proteggere i nostri clienti. Questo potrebbe significare che renderemo disponibile un aggiornamento della sicurezza attraverso il nostro processo di rilascio mensile o che distribuiremo un aggiornamento di sicurezza al di fuori delle date canoniche, a seconda delle esigenze dei clienti&#8221;<\/p>\n<h2>Riduzione del rischio per CVE-2023-36884<\/h2>\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2023-36884\" target=\"_blank\" rel=\"noopener\">Secondo Microsoft<\/a>, attualmente le aziende possono proteggersi in tre modi:<\/p>\n<ol>\n<li>I clienti che utilizzano Microsoft Defender per Office sono protetti dagli allegati che tentano di sfruttare questa vulnerabilit\u00e0.<\/li>\n<li>Per come sono strutturati attualmente gli di attacchi, l&#8217;applicazione della regola di Attack Surface Reduction (ASR) <a href=\"https:\/\/learn.microsoft.com\/en-us\/microsoft-365\/security\/defender-endpoint\/attack-surface-reduction-rules-reference?view=o365-worldwide#block-all-office-applications-from-creating-child-processes\" target=\"_blank\" rel=\"noopener\">\u00a0\u201dImpedisci a tutte le applicazioni Office di creare processi figli\u201d<\/a>\u00a0 impedisce lo sfruttamento della vulnerabilit\u00e0.<\/li>\n<li>Le organizzazioni che non possono usufruire di queste protezioni, potranno aggiungere i seguenti nomi di applicazioni a questa chiave di registro, come valori di tipo REG_DWORD con dati 1.: ComputerHKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftInternet ExplorerMainFeatureControlFEATURE_BLOCK_CROSS_PROTOCOL_FILE_NAVIGATION<\/li>\n<\/ol>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li>Excel.exe<\/li>\n<li>Graph.exe<\/li>\n<li>MSAccess.exe<\/li>\n<li>MSPub.exe<\/li>\n<li>PowerPoint.exe<\/li>\n<li>Visio.exe<\/li>\n<li>WinProj.exe<\/li>\n<li>WinWord.exe<\/li>\n<li>Wordpad.exe<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p style=\"padding-left: 40px;\"><strong>Nota: <\/strong>Microsoft dichiara che, sebbene queste impostazioni del registro di sistema possano ridurre il rischio di sfruttamento della vulnerabiit\u00e0,\u00a0 potrebbero anche compromettere la regolare funzionalit\u00e0 di queste applicazioni in alcune situazioni d\u2019uso. Pertanto, \u00e8 importante eseguire dei test prima di distribuire le modifiche su larga scala.<\/p>\n<h2>Come ridurre il rischio legato a CVE-2023-36884\u00a0utilizzando PowerShell<\/h2>\n<p>Per coloro che intendono apportare le modifiche al registro,\u00a0il nostro Software Product Engineer Kyle Bohlander ha creato il seguente script che automatizza il processo. L&#8217;utilizzo di questo script con Ninja (o con l&#8217;RMM di vostra scelta) ti consentir\u00e0 di distribuire la risoluzione in remoto e su larga scala. <strong>Nota:<\/strong> Questo script non \u00e8 limitato ai soli utenti di NinjaOne. Pu\u00f2 essere utilizzato da chiunque. Come consiglia Microsoft, tuttavia, questa risoluzione dovrebbe essere distribuita su macchine di test prima di una distribuzione pi\u00f9 ampia. Come al solito, se decidessi di eseguirlo, lo faresti a tuo rischio e pericolo. <strong>Requisiti del dispositivo: <\/strong>Funziona su sistemi Windows 7 e Windows Server 2008 e successivi. <strong>Se dovessi avere bisogno di ripristinare la situazione precedente all\u2019applicazione della risoluzione:<\/strong> Le impostazioni della chiave di registro possono essere annullate con il parametro -Undo o applicate a prodotti Office specifici con il parametro -OfficeProducts.<\/p>\n<blockquote><p><img decoding=\"async\" class=\"alignleft size-thumbnail wp-image-162511\" src=\"https:\/\/www.ninjaone.com\/wp-content\/uploads\/2024\/02\/kyle-bohlander-80x80-1.png\" alt=\"\" width=\"80\" height=\"80\" \/>Autore dello script: <strong>Kyle Bohlander, Software Product Engineer presso NinjaOne<\/strong><\/p><\/blockquote>\n<p><a href=\"https:\/\/go.ninjaone.com\/l\/652283\/2023-07-13\/4dhscy\/652283\/1689270503D3a9HKAS\/CVE_2023_36844.ps1\" target=\"_blank\" rel=\"noopener\">Scarica il file dello script qui<\/a>.<br \/>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\">&lt;#\r\n.SYNOPSIS\r\n    This script will set the registry keys required to remediate CVE-2023-36884. Please note that these keys may effect regular functionality of Microsoft Office Products. \r\n    These changes can be undone with the -Undo parameter or applied only to specific office products using the -OfficeProducts parameter.\r\n.DESCRIPTION\r\n    This script will set the registry keys required to remediate CVE-2023-36884. Please note that these keys may effect regular functionality of Microsoft Office Products. \r\n    These changes can be undone with the -Undo parameter or applied only to specific office products using the -OfficeProducts parameter.\r\n.EXAMPLE\r\n    (No Parameters)\r\n    \r\n    Visio was selected for remediation.\r\n    Set Registry::HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftInternet ExplorerMainFeatureControlFEATURE_BLOCK_CROSS_PROTOCOL_FILE_NAVIGATIONVisio.exe to 1\r\n    Success!\r\n    Word was selected for remediation.\r\n    Set Registry::HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftInternet ExplorerMainFeatureControlFEATURE_BLOCK_CROSS_PROTOCOL_FILE_NAVIGATIONWinWord.exe to 1\r\n    Success!\r\n    Wordpad was selected for remediation.\r\n    Set Registry::HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftInternet ExplorerMainFeatureControlFEATURE_BLOCK_CROSS_PROTOCOL_FILE_NAVIGATIONWordpad.exe to 1\r\n    Success!\r\n    Project was selected for remediation.\r\n    Set Registry::HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftInternet ExplorerMainFeatureControlFEATURE_BLOCK_CROSS_PROTOCOL_FILE_NAVIGATIONWinProj.exe to 1\r\n    Success!\r\n    PowerPoint was selected for remediation.\r\n    Set Registry::HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftInternet ExplorerMainFeatureControlFEATURE_BLOCK_CROSS_PROTOCOL_FILE_NAVIGATIONPowerPoint.exe to 1\r\n    Success!\r\n    Excel was selected for remediation.\r\n    Set Registry::HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftInternet ExplorerMainFeatureControlFEATURE_BLOCK_CROSS_PROTOCOL_FILE_NAVIGATIONExcel.exe to 1\r\n    Success!\r\n    Publisher was selected for remediation.\r\n    Set Registry::HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftInternet ExplorerMainFeatureControlFEATURE_BLOCK_CROSS_PROTOCOL_FILE_NAVIGATIONMsPub.exe to 1\r\n    Success!\r\n    Graph was selected for remediation.\r\n    Set Registry::HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftInternet ExplorerMainFeatureControlFEATURE_BLOCK_CROSS_PROTOCOL_FILE_NAVIGATIONGraph.exe to 1\r\n    Success!\r\n    Access was selected for remediation.\r\n    Set Registry::HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftInternet ExplorerMainFeatureControlFEATURE_BLOCK_CROSS_PROTOCOL_FILE_NAVIGATIONMSAccess.exe to 1\r\n    Success!\r\n\u200b\r\nPARAMETER: -Undo\r\n    Remove's the registry keys used for this fix (if they're set at all).\r\n.EXAMPLE\r\n    -Undo\r\n    \r\n    Visio was selected for remediation.\r\n    Succesfully removed registry key!\r\n    Word was selected for remediation.\r\n    Succesfully removed registry key!\r\n    Wordpad was selected for remediation.\r\n    Succesfully removed registry key!\r\n    Project was selected for remediation.\r\n    Succesfully removed registry key!\r\n    PowerPoint was selected for remediation.\r\n    Succesfully removed registry key!\r\n    Excel was selected for remediation.\r\n    Succesfully removed registry key!\r\n    Publisher was selected for remediation.\r\n    Succesfully removed registry key!\r\n    Graph was selected for remediation.\r\n    Succesfully removed registry key!\r\n    Access was selected for remediation.\r\n    Succesfully removed registry key!\r\n\u200b\r\nPARAMETER: -OfficeProducts \"Excel,Word\"\r\n    Set's the registry key for only those products. Can be given an individual product or a comma seperated list. Can also be used in combination with the -Undo parameter Ex. \"Publisher\" or \"Word,Excel,Access\"\r\n.EXAMPLE\r\n    -OfficeProducts \"Excel,Word\"\r\n    \r\n    Word was selected for remediation.\r\n    Set Registry::HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftInternet ExplorerMainFeatureControlFEATURE_BLOCK_CROSS_PROTOCOL_FILE_NAVIGATIONWinWord.exe to 1\r\n    Success!\r\n    Excel was selected for remediation.\r\n    Set Registry::HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftInternet ExplorerMainFeatureControlFEATURE_BLOCK_CROSS_PROTOCOL_FILE_NAVIGATIONExcel.exe to 1\r\n    Success!\r\n\u200b\r\n.OUTPUTS\r\n    None\r\n.NOTES\r\n    General notes\r\n#&gt;\r\n[CmdletBinding()]\r\nparam (\r\n    [Parameter()]\r\n    [String]$OfficeProducts = \"All\",\r\n    [Parameter()]\r\n    [Switch]$Undo\r\n)\r\n\u200b\r\nbegin {\r\n\u200b\r\n    # Test's if the script is running in an elevated fashion (required for HKLM edits)\r\n    function Test-IsElevated {\r\n        $id = [System.Security.Principal.WindowsIdentity]::GetCurrent()\r\n        $p = New-Object System.Security.Principal.WindowsPrincipal($id)\r\n        $p.IsInRole([System.Security.Principal.WindowsBuiltInRole]::Administrator)\r\n    }\r\n\u200b\r\n    # This is just to make setting regkey's easier\r\n    function Set-RegKey {\r\n        param (\r\n            $Path,\r\n            $Name,\r\n            $Value,\r\n            [ValidateSet(\"DWord\", \"QWord\", \"String\", \"ExpandedString\", \"Binary\", \"MultiString\", \"Unknown\")]\r\n            $PropertyType = \"DWord\"\r\n        )\r\n        if (-not $(Test-Path -Path $Path)) {\r\n            # Check if path does not exist and create the path\r\n            New-Item -Path $Path -Force | Out-Null\r\n        }\r\n        if ((Get-ItemProperty -Path $Path -Name $Name -ErrorAction SilentlyContinue)) {\r\n            # Update property and print out what it was changed from and changed to\r\n            $CurrentValue = (Get-ItemProperty -Path $Path -Name $Name -ErrorAction SilentlyContinue).$Name\r\n            try {\r\n                Set-ItemProperty -Path $Path -Name $Name -Value $Value -Force -Confirm:$false -ErrorAction Stop | Out-Null\r\n            }\r\n            catch {\r\n                Write-Error \"[Error] Unable to Set registry key for $Name please see below error!\"\r\n                Write-Error $_\r\n                exit 1\r\n            }\r\n            Write-Host \"$Path$Name changed from $CurrentValue to $($(Get-ItemProperty -Path $Path -Name $Name -ErrorAction SilentlyContinue).$Name)\"\r\n        }\r\n        else {\r\n            # Create property with value\r\n            try {\r\n                New-ItemProperty -Path $Path -Name $Name -Value $Value -PropertyType $PropertyType -Force -Confirm:$false -ErrorAction Stop | Out-Null\r\n            }\r\n            catch {\r\n                Write-Error \"[Error] Unable to Set registry key for $Name please see below error!\"\r\n                Write-Error $_\r\n                exit 1\r\n            }\r\n            Write-Host \"Set $Path$Name to $($(Get-ItemProperty -Path $Path -Name $Name -ErrorAction SilentlyContinue).$Name)\"\r\n        }\r\n    }\r\n\u200b\r\n    # All the microsoft office products with their corresponding dword value\r\n    $RemediationValues = @{ \"Excel\" = \"Excel.exe\"; \"Graph\" = \"Graph.exe\"; \"Access\" = \"MSAccess.exe\"; \"Publisher\" = \"MsPub.exe\"; \"PowerPoint\" = \"PowerPnt.exe\"; \"OldPowerPoint\" = \"PowerPoint.exe\" ; \"Visio\" = \"Visio.exe\"; \"Project\" = \"WinProj.exe\"; \"Word\" = \"WinWord.exe\"; \"Wordpad\" = \"Wordpad.exe\" }\r\n}\r\nprocess {\r\n\u200b\r\n    # Error out when not elevated\r\n    if (-not (Test-IsElevated)) {\r\n        Write-Error -Message \"Access Denied. Please run with Administrator privileges.\"\r\n        exit 1\r\n    }\r\n\u200b\r\n    # If they have a smaller selection we'll want to filter our remediation list\r\n    if ($OfficeProducts -notlike \"All\") {\r\n        $OfficeProducts = $OfficeProducts.split(',') | ForEach-Object { $_.Trim() }\r\n        $RemediationTargets = $RemediationValues.GetEnumerator() | ForEach-Object { $_ | Where-Object { $OfficeProducts -match $_.Key } }\r\n    }\r\n    else {\r\n        $RemediationTargets = $RemediationValues.GetEnumerator()\r\n    }\r\n\u200b\r\n    # Path to all the registry keys\r\n    $Path = \"Registry::HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftInternet ExplorerMainFeatureControlFEATURE_BLOCK_CROSS_PROTOCOL_FILE_NAVIGATION\"\r\n\u200b\r\n    # We'll want to display an error if we don't have anything to do\r\n    if ($RemediationTargets) { \r\n\u200b\r\n        # For Each product we're targeting we'll set the regkey. The Set-RegKey function already checks if it was succesful and will display an error and exit if it fails\r\n        $RemediationTargets | ForEach-Object { \r\n            Write-Host \"$($_.Name) was selected for remediation.\"\r\n            if (-not $Undo) {\r\n                Set-RegKey -Path $Path -Name $_.Value -Value 1\r\n                Write-Host \"Success!\"\r\n            }\r\n            else {\r\n                # If you only applied it to certain products this will error so instead we'll hide the errors and check afterwards if the registry key is there.\r\n                Remove-ItemProperty -Path $Path -Name $_.Value -ErrorAction SilentlyContinue | Out-Null\r\n                if (Get-ItemProperty -Path $Path -Name $_.Value -ErrorAction SilentlyContinue) {\r\n                    Write-Error \"[Error] Unable to undo registry key $($_.Value)!\"\r\n                    exit 1\r\n                }\r\n                else {\r\n                    Write-Host \"Succesfully removed registry key!\"\r\n                }\r\n            }\r\n        }\r\n\u200b\r\n        Write-Warning \"A reboot may be required.\"\r\n        exit 0\r\n    }\r\n    else {\r\n        Write-Host $RemediationTargets\r\n        Write-Warning \"No products were selected! The valid value's for -OfficeProducts is listed below you can also use a comma seperated list or simply put 'All'.\"\r\n        $RemediationValues | Sort-Object Name | Format-Table | Out-String | Write-Host\r\n        Write-Error \"ERROR: Nothing to do!\"\r\n        exit 1\r\n    }\r\n}<\/pre>\n<p>&nbsp;<\/p>\n<\/p>\n","protected":false},"author":28,"featured_media":140558,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"_relevanssi_hide_post":"","_relevanssi_hide_content":"","_relevanssi_pin_for_all":"","_relevanssi_pin_keywords":"","_relevanssi_unpin_keywords":"","_relevanssi_related_keywords":"","_relevanssi_related_include_ids":"","_relevanssi_related_exclude_ids":"","_relevanssi_related_no_append":"","_relevanssi_related_not_related":"","_relevanssi_related_posts":"","_relevanssi_noindex_reason":"","_lmt_disableupdate":"no","_lmt_disable":""},"operating_system":[4212],"use_cases":[4272],"class_list":["post-208090","script_hub","type-script_hub","status-publish","has-post-thumbnail","hentry","script_hub_category-windows"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.ninjaone.com\/it\/wp-json\/wp\/v2\/script_hub\/208090","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ninjaone.com\/it\/wp-json\/wp\/v2\/script_hub"}],"about":[{"href":"https:\/\/www.ninjaone.com\/it\/wp-json\/wp\/v2\/types\/script_hub"}],"author":[{"embeddable":true,"href":"https:\/\/www.ninjaone.com\/it\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ninjaone.com\/it\/wp-json\/wp\/v2\/comments?post=208090"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.ninjaone.com\/it\/wp-json\/wp\/v2\/media\/140558"}],"wp:attachment":[{"href":"https:\/\/www.ninjaone.com\/it\/wp-json\/wp\/v2\/media?parent=208090"}],"wp:term":[{"taxonomy":"script_hub_category","embeddable":true,"href":"https:\/\/www.ninjaone.com\/it\/wp-json\/wp\/v2\/operating_system?post=208090"},{"taxonomy":"use_cases","embeddable":true,"href":"https:\/\/www.ninjaone.com\/it\/wp-json\/wp\/v2\/use_cases?post=208090"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}