Snort mailing list archives

Snort Subscriber Rules Update 2020-12-08


From: Research <research () sourcefire com>
Date: Tue, 8 Dec 2020 18:38:04 GMT

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


Talos Snort Subscriber Rules Update

Synopsis:
Talos is aware of vulnerabilities affecting products from Microsoft
Corporation.

Details:
Microsoft Vulnerability CVE-2020-17096:
A coding deficiency exists in NTFS that may lead to remote code
execution.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 56561 through 56562.

Microsoft Vulnerability CVE-2020-17121:
A coding deficiency exists in Microsoft SharePoint that may lead to
remote code execution.

A rule to detect attacks targeting this vulnerability is included in
this release and is identified with GID 1, SID 56560.

Microsoft Vulnerability CVE-2020-17144:
A coding deficiency exists in Microsoft Exchange that may lead to
remote code execution.

A rule to detect attacks targeting this vulnerability is included in
this release and is identified with GID 1, SID 56554.

Microsoft Vulnerability CVE-2020-17152:
A coding deficiency exists in Microsoft Dynamics 365 for Finance and
Operations (on-premises) that may lead to remote code execution.

A rule to detect attacks targeting this vulnerability is included in
this release and is identified with GID 1, SID 56558.

Microsoft Vulnerability CVE-2020-17158:
A coding deficiency exists in Microsoft Dynamics 365 for Finance and
Operations (on-premises) that may lead to remote code execution.

A rule to detect attacks targeting this vulnerability is included in
this release and is identified with GID 1, SID 56557.

Talos also has added and modified multiple rules in the
file-multimedia, malware-other, os-windows, policy-other and
server-webapp rule sets to provide coverage for emerging threats from
these technologies.


For a complete list of new and modified rules please see:

https://www.snort.org/advisories
-----BEGIN PGP SIGNATURE-----

iQIcBAEBAgAGBQJfz8gMAAoJEPE/nha8pb+tOOoP/1Cpu3MyFcHnF5hFqRSjB1WD
+K41S35gxpRJ7Uj4GrtcfdaqAAckz0wyxzTEvAY4/SgiXPOk2V9OgIXjYbGtWsOr
I/2fwOH/kQtOGlEinTr4jfVcTNBXd23yrTHqHCHrsfoTTzWnqlpD0YhBmcE06MX6
Euh7P+LI/8Z0NOY87R4a9iPLb+/UEBalJ0cj1k5x5u5CZAgLqHxZi0Qhw/t4nAMS
X+hQtaG0/ndvWyqGwzfsURuX5Ga2ezqpadrLQwB11vJ5STZLo8k2ifhMaF+OrMjw
5FY17gnKJW7gGSGtKNzYLK4nl2kLs9nGZPKlhcdOIuA7A3XBBj+n4cvj7bxtnXjk
8EGGgE74j2KjkUNmjcZIWeDd/ng48fhzGARsCoiO6QjXerTnUsjM8ThosBvRGdvB
CuTkMegnkksMiGmryYowDb64w+yP9uYJ6EuEj5RfMdtmQZmPqF8+k5ubNnLxvqAa
NL4d7qizV5ahpu5brghAmFzePzEHA+iGM5EwUCezMD5TmFP6L9mJ3XlzQIdET+GH
HgUG2JWJTI9OOylmS9//2AgTq1nFkraO0H4QMvEKrO43tLqj4+fGp73kIntHI/Ks
zXkvO4z6l01jfFrh0adPMVLQD4zAQ3kYeMAzXAAz52TAX80S8i8lyxCwkceAWJTO
O45rXmhjWZPW127dW9Dl
=nweV
-----END PGP SIGNATURE-----

_______________________________________________
Snort-sigs mailing list
Snort-sigs () lists snort org
https://lists.snort.org/mailman/listinfo/snort-sigs

Please visit http://blog.snort.org for the latest news about Snort!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a 
href=" https://snort.org/downloads/#rule-downloads";>emerging threats</a>!


Current thread: