Snort mailing list archives

Snort Subscriber Rules Update 2021-05-11


From: Research <research () sourcefire com>
Date: Tue, 11 May 2021 18:29:14 GMT

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


Talos Snort Subscriber Rules Update

Synopsis:
Talos is aware of vulnerabilities affecting products from Microsoft
Corporation.

Details:
Microsoft Vulnerability CVE-2021-26419:
A coding deficiency exists in Microsoft Scripting Engine that may lead
to remote code execution.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 57542 through 57543.

Microsoft Vulnerability CVE-2021-31166:
A coding deficiency exists in HTTP Protocol Stack that may lead to
remote code execution.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 57549 through 57550.

Microsoft Vulnerability CVE-2021-31170:
A coding deficiency exists in Microsoft Graphics Component that may
lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 57539 through 57540.

Microsoft Vulnerability CVE-2021-31181:
A coding deficiency exists in Microsoft SharePoint that may lead to
remote code execution.

A rule to detect attacks targeting this vulnerability is included in
this release and is identified with GID 1, SID 57548.

Microsoft Vulnerability CVE-2021-31188:
A coding deficiency exists in Microsoft Graphics Component that may
lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 57544 through 57545.

Talos also has added and modified multiple rules in the browser-ie,
file-image, file-other, malware-backdoor, os-windows and server-webapp
rule sets to provide coverage for emerging threats from these
technologies.


For a complete list of new and modified rules please see:

https://www.snort.org/advisories
-----BEGIN PGP SIGNATURE-----

iQIcBAEBAgAGBQJgmsz4AAoJEGCbAk8rPt0Hlp8QAKjzss3DEndVMpK/y1kuzysH
jZa67ML7YWRfkZrxECMjc5pPpO5PKFtJTmzhViYJBl0BK0aF4QtxgFWFhG2Cd4Ty
ipNDLt9uTAUgtDqdzUsw6mN7wFdVbreoCnwDA/yErCZhXOxV5aXWnS7SVinZ3AUr
M/Wb12G5H9coklUdl4x7wf6LDiq1G/3j9+q3rPkS+pI0lWWi0CkwC1L8VU6Xpo0Y
NvVwSZiy54HPOiQd7l9Nig1Iunf9+87f0GD0R1mvy3USBoI9fK7E4gcruFbg9aMY
nZGX/vXrn+IXCbkjn2Rh1tkne2NqoGM1Q/3KsB7V4itfjPTyp/Gi7XobARbg2XfU
e7JNhK0wkfUrHIexNkKBDuDiQIrIiHO0WuWCF2R0DZE3KIFPkg5gZN8xTLBALqV9
/lt4oujbGcEA+01i0w+l86GDyElSFksU2RogNspQqQdHWle3ZfoLY4c2dVjgHNHI
2CneDpaGIwSJHslE9kKAcOmf9aS3IpbB85ymKU0za/mSJCDt695OGN0M68GQuWaM
MPSAPe2Hp7hhTSJ/AMIkadIsWNubNwiFT3xK00Yi7QZtcnZnoTwv09yKYWkrR2fV
aN+/6TRp++R0laCp8ZXgaDy/ZAb40h8cOuWAS76rCYDde0y/uonq24KwM4B1p1dG
CY8iJmuP4tExwNoCY7B/
=5Irf
-----END PGP SIGNATURE-----

_______________________________________________
Snort-sigs mailing list
Snort-sigs () lists snort org
https://lists.snort.org/mailman/listinfo/snort-sigs

Please visit http://blog.snort.org for the latest news about Snort!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a 
href=" https://snort.org/downloads/#rule-downloads";>emerging threats</a>!


Current thread: