Snort mailing list archives

Snort Subscriber Rules Update 2021-01-12


From: Research <research () sourcefire com>
Date: Tue, 12 Jan 2021 18:45:30 GMT

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


Talos Snort Subscriber Rules Update

Synopsis:
Talos is aware of vulnerabilities affecting products from Microsoft
Corporation.

Details:
Microsoft Vulnerability CVE-2021-1647:
A coding deficiency exists in Microsoft Defender that may lead to
remote code execution.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 56857 through 56860.

Microsoft Vulnerability CVE-2021-1707:
A coding deficiency exists in Microsoft SharePoint that may lead to
remote code execution.

A rule to detect attacks targeting this vulnerability is included in
this release and is identified with GID 1, SID 56865.

Microsoft Vulnerability CVE-2021-1709:
A coding deficiency exists in Microsoft Win32k that may lead to an
escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 56849 through 56856.

Talos also has added and modified multiple rules in the browser-other,
content-replace, file-executable, file-other, malware-cnc, os-windows
and server-webapp rule sets to provide coverage for emerging threats
from these technologies.


For a complete list of new and modified rules please see:

https://www.snort.org/advisories
-----BEGIN PGP SIGNATURE-----

iQIcBAEBAgAGBQJf/e5JAAoJEPE/nha8pb+t6NoP/3hulZ54JNUdJUyaDLzHO+Yh
jxGJIVxXI8QPTVk5KvnyAzMIbdkXYMLk9o9bCfXrMGoOlaAylwgUn4j5vb3fd27H
GjgmlbNRO3sULjZFkkmCTWr+3qacaHcQ7VV3BuTFI0KsFa2jynYPAphmoZUdlqQM
ke2pJMZoOD4LW3mzrVGSV3FMA5Kl4BSAUkTXIWr/86HlgLi0+Np6txiqbC0LT269
8ibZT23dCB5YCZiXAATiHhYE2lW4jOJtknzJ97RurAvYlBq6ecQmBmS3VmaQU/4d
iWbEgHAxAea119ZjKALvU1OpfuipeXuIKviKaKzFy9bd7D24I5+6Ab+rOAeHvPgD
mEaayWeYUtd/ArkPn68mG3UasNpwNWsPabs/kWIKY06bITLrYUMeudCXfZFFPGIt
QhQBsyIM07x3Cvm5CQ1PBW40s4AYaIyCopBOsyxHGHu4kd0N/rAf5DEvtq3eN3jG
taIs3k+Q0Tz/8ngsUBnb24k78i/xHrprYAAGJEpYmHOqO5fOXYE4fNsb4hj+sQ1i
YRIsOH+IZbUYDsg03Sv4WAjTCNKiBNlVBtOZu8ho4wDLtpIFhIAFKt9VQUSIiF7r
GXVv6Al+rwGxB0UqUKo4Q3akdJwy8tySiq1a9qvP+cLCkRSgHDhFBXTCpljxrRYd
MCRh3sj4xOYTDaTyE2PI
=gYXV
-----END PGP SIGNATURE-----

_______________________________________________
Snort-sigs mailing list
Snort-sigs () lists snort org
https://lists.snort.org/mailman/listinfo/snort-sigs

Please visit http://blog.snort.org for the latest news about Snort!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a 
href=" https://snort.org/downloads/#rule-downloads";>emerging threats</a>!


Current thread: