Snort mailing list archives
Snort Subscriber Rules Update 2021-12-14
From: Research <research () sourcefire com>
Date: Tue, 14 Dec 2021 18:37:25 GMT
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Talos Snort Subscriber Rules Update Synopsis: Talos is aware of vulnerabilities affecting products from Microsoft Corporation. Details: Microsoft Vulnerability CVE-2021-41333: A coding deficiency exists in Microsoft Windows Print Spooler that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with GID 1, SIDs 58752 through 58753. Microsoft Vulnerability CVE-2021-43207: A coding deficiency exists in Microsoft Windows Common Log File System driver that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with GID 1, SIDs 58775 through 58776. Microsoft Vulnerability CVE-2021-43226: A coding deficiency exists in Microsoft Windows Common Log File System driver that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with GID 1, SIDs 58754 through 58757. Microsoft Vulnerability CVE-2021-43233: A coding deficiency exists in Remote Desktop Client that may lead to remote code execution. A rule to detect attacks targeting this vulnerability is included in this release and is identified with GID 1, SID 58774. Microsoft Vulnerability CVE-2021-43883: A coding deficiency exists in Microsoft Windows Installer that may lead to an escalation of privilege. Previously released rules will detect attacks targeting these vulnerabilities and have been updated with the appropriate reference information. They are also included in this release and are identified with GID 1, SIDs 58635 through 58636. Talos is releasing updates to Snort 2 SIDs: 58740-58741 and new Snort 2 SIDs: 58784-58790 to address CVE-2021-44228, an RCE vulnerability in the Apache Log4j API. Talos has also added and modified multiple rules in the file-pdf, malware-cnc, malware-other, os-windows and server-other rule sets to provide coverage for emerging threats from these technologies. For a complete list of new and modified rules please see: https://www.snort.org/advisories -----BEGIN PGP SIGNATURE----- iQIcBAEBAgAGBQJhuORkAAoJEGCbAk8rPt0HPy4QAIRd4oeTY0HO61WdIXIYd+yA FBxt4++MNOuyHsf8JA7PRhjAj85cfzgDyy6Wairi85LSRQpNva5jHYoC8KdgNyXQ 4Srgj6a2qCSHEdaZ97oBBF+iNln9To0FhaUJwSo6V2cudqjqid0Tyyx38BIPNnlS qpKKnOYwix0xRTkJoqKy51MPzi6ecvSAMlyoakQ6SPst9SQtMmsZXNhPlJeX5ric x8GsJ3wM9yhO5GwvA3xRoMysbIkLb6eJ4L8SNAiVg/g+w6+IV2VbQnAncH5V9nEt G5Jo3e0QZ0VI3+pbKZDazyRWqFRrycehjuQagAMWzhOVdhDmH8KNUlJJHjjSANLW ADD+K9dxi83pDSzprc6yDPvLhirU48ocJ2dIr8jr4IYqvdplw0la6eWi1JXui9GN ucWMWVH0y8xaJb9Z+kSRwD6rMwPSSuNj7SRnCJTWfhh7nBcmNoHox62ayG9WgPmn 6yAm2DnxVAxnSKyxtrpvbSJDR/UTxPQNRJtURR+rSP0Nl97DS8cwCHpkYpCTIm7I P6W09AarHr98mqi3tMAFfztJBGIlbGLhEBN1HtYRlQRa86qzH/i9K+ByBUyW2dDm wIQdQh6Dh6MlLrW2jR0eukQm9ra/0JlFse3amwf1QQi85QmkVBwPjGOr0K7SFcjH 6qiedTZc8IuW+Pxgkfvw =vpUU -----END PGP SIGNATURE----- _______________________________________________ Snort-sigs mailing list Snort-sigs () lists snort org https://lists.snort.org/mailman/listinfo/snort-sigs Please visit http://blog.snort.org for the latest news about Snort! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a href=" https://snort.org/downloads/#rule-downloads">emerging threats</a>!
Current thread:
- Snort Subscriber Rules Update 2021-12-14 Research (Dec 14)