Snort Subscriber Rules Update 2023-06-13
Research <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.sigs |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Talos Snort Subscriber Rules Update Synopsis: Talos is aware of vulnerabilities affecting products from Microsoft Corporation. Details: Microsoft Vulnerability CVE-2023-28310: A coding deficiency exists in Microsoft Exchange Server that may lead to remote code execution. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort2: GID 1, SIDs 61933 through 61935, Snort3: GID 1, SIDs 61933 and 300600. Microsoft Vulnerability CVE-2023-29357: A coding deficiency exists in Microsoft SharePoint Server that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort2: GID 1, SIDs 61937 through 61939, Snort3: GID 1, SIDs 61937 through 61939. Microsoft Vulnerability CVE-2023-29358: A coding deficiency exists in Microsoft Windows GDI that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort2: GID 1, SIDs 61909 through 61910, Snort3: GID 1, SID 300592. Microsoft Vulnerability CVE-2023-29360: A coding deficiency exists in Microsoft Windows TPM Device Driver that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort2: GID 1, SIDs 61915 through 61916, Snort3: GID 1, SID 300595. Microsoft Vulnerability CVE-2023-29361: A coding deficiency exists in Microsoft Windows Cloud Files Mini Filter Driver that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort2: GID 1, SIDs 61907 through 61908, Snort3: GID 1, SID 300591. Microsoft Vulnerability CVE-2023-29371: A coding deficiency exists in Microsoft Windows GDI that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort2: GID 1, SIDs 61911 through 61912, Snort3: GID 1, SID 300593. Talos also has added and modified multiple rules in the file-other, malware-backdoor, malware-cnc, malware-other, malware-tools, os-windows, policy-other and server-webapp rule sets to provide coverage for emerging threats from these technologies. For a complete list of new and modified rules please see: https://www.snort.org/advisories -----BEGIN PGP SIGNATURE----- iQIcBAEBAgAGBQJkiLa0AAoJEMzg39Iewam/TqYP/16tFbRZ4AMVxAmsnQQMuuMu HC92mJDBH4t19CIOGSsZ1/L3evOPWiWOaEWNXnzzM3+n0dmT1Ta4B6ToDdbVqevX Wy/n44I3uYnkVcXmWR/i/yMXjf1Vbc6kMOWqxWu1On408EM7nxFWs06eOADS9Cka EqzEXu5+Csmbtt+VABkAiXxKjEFBEJVa0v1DWrUgILiyY93EFM/RZIva7dSWCew9 hC7Ga9JtNXWqrxMN2y1cK6OFUDQ9qy5Wd3WDAWIwIbHoSZj6RHgplwA3nH+tg0xP e29muBhZJYqboMK5lkC7cRbF6YeHkwCfdq4guCNHqrpxA94rUPwX2z3ks/j+uSKR wm7/ndbHTrKxNPyMfO74W90c7OCdDuwj58w4dd0ELSQxueWkfh2V7nn+KamdMlLf i5QwY1DIXLYZew9iy9wIDa4L16jCHmscXKqss+oVIoEy3DCgOFIk4p3ld7pXwe1l P2adpZcnsXvo+t5jFFrUmbAIqdpS5csF3TlFHHbGLGXLiqZRs+4dU7PckXRCvX49 xJ/KaMi72yozYukWSbvVNBMA7MKJSldlj9+UOVzmxCE5d2dha0DVZw/+Rz6fU0Ao x/E7v6wdEqx8lHMwdNwbGnkHQfVyv/55xfqCmfly7+GR0H6X8nJw1NQE5W3JYZ+6 Vlwv6y/eNhELuOaXl9Z8 =2C/G -----END PGP SIGNATURE----- _______________________________________________ Snort-sigs mailing list [email protected] https://lists.snort.org/mailman/listinfo/snort-sigs Please visit http://blog.snort.org for the latest news about Snort! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a href=" https://snort.org/downloads/#rule-downloads">emerging threats</a>!