Snort Subscriber Rules Update 2023-06-13

Research <[email protected]>
Newsgroups gmane.comp.security.ids.snort.sigs
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


Talos Snort Subscriber Rules Update

Synopsis:
Talos is aware of vulnerabilities affecting products from Microsoft
Corporation.

Details:
Microsoft Vulnerability CVE-2023-28310:
A coding deficiency exists in Microsoft Exchange Server that may lead
to remote code execution.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort2: GID 1, SIDs 61933 through 61935,
Snort3: GID 1, SIDs 61933 and 300600.

Microsoft Vulnerability CVE-2023-29357:
A coding deficiency exists in Microsoft SharePoint Server that may lead
to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort2: GID 1, SIDs 61937 through 61939,
Snort3: GID 1, SIDs 61937 through 61939.

Microsoft Vulnerability CVE-2023-29358:
A coding deficiency exists in Microsoft Windows GDI that may lead to an
escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort2: GID 1, SIDs 61909 through 61910,
Snort3: GID 1, SID 300592.

Microsoft Vulnerability CVE-2023-29360:
A coding deficiency exists in Microsoft Windows TPM Device Driver that
may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort2: GID 1, SIDs 61915 through 61916,
Snort3: GID 1, SID 300595.

Microsoft Vulnerability CVE-2023-29361:
A coding deficiency exists in Microsoft Windows Cloud Files Mini Filter
Driver that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort2: GID 1, SIDs 61907 through 61908,
Snort3: GID 1, SID 300591.

Microsoft Vulnerability CVE-2023-29371:
A coding deficiency exists in Microsoft Windows GDI that may lead to an
escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort2: GID 1, SIDs 61911 through 61912,
Snort3: GID 1, SID 300593.

Talos also has added and modified multiple rules in the file-other,
malware-backdoor, malware-cnc, malware-other, malware-tools,
os-windows, policy-other and server-webapp rule sets to provide
coverage for emerging threats from these technologies.


For a complete list of new and modified rules please see:

https://www.snort.org/advisories
-----BEGIN PGP SIGNATURE-----

iQIcBAEBAgAGBQJkiLa0AAoJEMzg39Iewam/TqYP/16tFbRZ4AMVxAmsnQQMuuMu
HC92mJDBH4t19CIOGSsZ1/L3evOPWiWOaEWNXnzzM3+n0dmT1Ta4B6ToDdbVqevX
Wy/n44I3uYnkVcXmWR/i/yMXjf1Vbc6kMOWqxWu1On408EM7nxFWs06eOADS9Cka
EqzEXu5+Csmbtt+VABkAiXxKjEFBEJVa0v1DWrUgILiyY93EFM/RZIva7dSWCew9
hC7Ga9JtNXWqrxMN2y1cK6OFUDQ9qy5Wd3WDAWIwIbHoSZj6RHgplwA3nH+tg0xP
e29muBhZJYqboMK5lkC7cRbF6YeHkwCfdq4guCNHqrpxA94rUPwX2z3ks/j+uSKR
wm7/ndbHTrKxNPyMfO74W90c7OCdDuwj58w4dd0ELSQxueWkfh2V7nn+KamdMlLf
i5QwY1DIXLYZew9iy9wIDa4L16jCHmscXKqss+oVIoEy3DCgOFIk4p3ld7pXwe1l
P2adpZcnsXvo+t5jFFrUmbAIqdpS5csF3TlFHHbGLGXLiqZRs+4dU7PckXRCvX49
xJ/KaMi72yozYukWSbvVNBMA7MKJSldlj9+UOVzmxCE5d2dha0DVZw/+Rz6fU0Ao
x/E7v6wdEqx8lHMwdNwbGnkHQfVyv/55xfqCmfly7+GR0H6X8nJw1NQE5W3JYZ+6
Vlwv6y/eNhELuOaXl9Z8
=2C/G
-----END PGP SIGNATURE-----

_______________________________________________
Snort-sigs mailing list
[email protected]
https://lists.snort.org/mailman/listinfo/snort-sigs

Please visit http://blog.snort.org for the latest news about Snort!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a href=" https://snort.org/downloads/#rule-downloads">emerging threats</a>!
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.