Snort mailing list archives

Snort Subscriber Rules Update 2021-12-14


From: Research <research () sourcefire com>
Date: Tue, 14 Dec 2021 18:37:25 GMT

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


Talos Snort Subscriber Rules Update

Synopsis:
Talos is aware of vulnerabilities affecting products from Microsoft
Corporation.

Details:
Microsoft Vulnerability CVE-2021-41333:
A coding deficiency exists in Microsoft Windows Print Spooler that may
lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 58752 through 58753.

Microsoft Vulnerability CVE-2021-43207:
A coding deficiency exists in Microsoft Windows Common Log File System
driver that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 58775 through 58776.

Microsoft Vulnerability CVE-2021-43226:
A coding deficiency exists in Microsoft Windows Common Log File System
driver that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 58754 through 58757.

Microsoft Vulnerability CVE-2021-43233:
A coding deficiency exists in Remote Desktop Client that may lead to
remote code execution.

A rule to detect attacks targeting this vulnerability is included in
this release and is identified with GID 1, SID 58774.

Microsoft Vulnerability CVE-2021-43883:
A coding deficiency exists in Microsoft Windows Installer that may lead
to an escalation of privilege.

Previously released rules will detect attacks targeting these
vulnerabilities and have been updated with the appropriate reference
information. They are also included in this release and are identified
with GID 1, SIDs 58635 through 58636.

Talos is releasing updates to Snort 2 SIDs: 58740-58741 and new Snort 2
SIDs: 58784-58790 to address CVE-2021-44228, an RCE vulnerability in
the Apache Log4j API.

Talos has also added and modified multiple rules in the file-pdf,
malware-cnc, malware-other, os-windows and server-other rule sets to
provide coverage for emerging threats from these technologies.


For a complete list of new and modified rules please see:

https://www.snort.org/advisories
-----BEGIN PGP SIGNATURE-----

iQIcBAEBAgAGBQJhuORkAAoJEGCbAk8rPt0HPy4QAIRd4oeTY0HO61WdIXIYd+yA
FBxt4++MNOuyHsf8JA7PRhjAj85cfzgDyy6Wairi85LSRQpNva5jHYoC8KdgNyXQ
4Srgj6a2qCSHEdaZ97oBBF+iNln9To0FhaUJwSo6V2cudqjqid0Tyyx38BIPNnlS
qpKKnOYwix0xRTkJoqKy51MPzi6ecvSAMlyoakQ6SPst9SQtMmsZXNhPlJeX5ric
x8GsJ3wM9yhO5GwvA3xRoMysbIkLb6eJ4L8SNAiVg/g+w6+IV2VbQnAncH5V9nEt
G5Jo3e0QZ0VI3+pbKZDazyRWqFRrycehjuQagAMWzhOVdhDmH8KNUlJJHjjSANLW
ADD+K9dxi83pDSzprc6yDPvLhirU48ocJ2dIr8jr4IYqvdplw0la6eWi1JXui9GN
ucWMWVH0y8xaJb9Z+kSRwD6rMwPSSuNj7SRnCJTWfhh7nBcmNoHox62ayG9WgPmn
6yAm2DnxVAxnSKyxtrpvbSJDR/UTxPQNRJtURR+rSP0Nl97DS8cwCHpkYpCTIm7I
P6W09AarHr98mqi3tMAFfztJBGIlbGLhEBN1HtYRlQRa86qzH/i9K+ByBUyW2dDm
wIQdQh6Dh6MlLrW2jR0eukQm9ra/0JlFse3amwf1QQi85QmkVBwPjGOr0K7SFcjH
6qiedTZc8IuW+Pxgkfvw
=vpUU
-----END PGP SIGNATURE-----

_______________________________________________
Snort-sigs mailing list
Snort-sigs () lists snort org
https://lists.snort.org/mailman/listinfo/snort-sigs

Please visit http://blog.snort.org for the latest news about Snort!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a 
href=" https://snort.org/downloads/#rule-downloads";>emerging threats</a>!


Current thread: