Snort Subscriber Rules Update 2025-12-09
Research via Snort-sigs <[email protected]> Tue, 9 Dec 2025 23:26:35 +0000 (GMT)
| Newsgroups | gmane.comp.security.ids.snort.sigs |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Talos Snort Subscriber Rules Update Synopsis: Talos is aware of vulnerabilities affecting products from Microsoft Corporation. Details: Microsoft Vulnerability CVE-2025-59516: A coding deficiency exists in Microsoft Windows Storage VSP Driver that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 65557 through 65558, Snort 3: GID 1, SID 301352. Microsoft Vulnerability CVE-2025-59517: A coding deficiency exists in Microsoft Windows Storage VSP Driver that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 65559 through 65560, Snort 3: GID 1, SID 301353. Microsoft Vulnerability CVE-2025-62221: A coding deficiency exists in Microsoft Windows Cloud Files Mini Filter Driver that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 65571 through 65572, Snort 3: GID 1, SID 301356. Microsoft Vulnerability CVE-2025-62454: A coding deficiency exists in Microsoft Windows Cloud Files Mini Filter Driver that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 65573 through 65574, Snort 3: GID 1, SID 301357. Microsoft Vulnerability CVE-2025-62458: A coding deficiency exists in Microsoft Win32k that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 62486 through 62487, Snort 3: GID 1, SID 300719. Microsoft Vulnerability CVE-2025-62470: A coding deficiency exists in Microsoft Windows Common Log File System Driver that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 65555 through 65556, Snort 3: GID 1, SID 301351. Microsoft Vulnerability CVE-2025-62472: A coding deficiency exists in Microsoft Windows Remote Access Connection Manager that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 65561 through 65562, Snort 3: GID 1, SID 301354. Talos has added and modified multiple rules in the file-other, malware-cnc, malware-other, os-windows and server-webapp rule sets to provide coverage for emerging threats from these technologies. For a complete list of new and modified rules please see: https://www.snort.org/advisories -----BEGIN PGP SIGNATURE----- iQIcBAEBAgAGBQJpOLAqAAoJEHB/DbSAg2dxlZgQAKy9JWbM4PGhGfLh+dgQRq5G ltZDFNZ7zvLHWvs/fQQTTgsusyA5xJwp/cevyUeGD4orTlo6wiwwmysV1i4vFo1b 1xhVM+v/BJDHD3LCi2eYIQ/3m3RXqODZTVo9CPKeNuKIigGlsrpT4MuuwbJ0bLcK 2KB1IMgXNzVcLVe3zrK5Ju9bFE/mG2b1lq3qBVXUG14WFu0zdd2T0eURPzCA2JJH kNi++sn4Gd12dFql3sIpRVzIRjuw7ai0UCLLYh6frYesSCiOKXozQpN5yjro7ILM TntfmC09ZSjfjw9rAuG7XVitDXylRdOsHc8d5SmWE2lK/3o8MSIKPwa0GCqOCPAN fOx6ceTDUjdIcOnXbXEVJMitRuchzVfk0LOgvW343SCVFHcbmw81BLmOzUeHZIWX OYBvRA91OwEXiTc2PC/52Cb7BgJN/Flg77ucKDQAoQH/HebOgRYJDoZ+CJMaKhBc bgHMoOiERQRTG+1UpGFuNGtYjohsJikwEojABpbunK+uRM9DC7fd3+l5WS5Dkd4L TCyt/W8JCM/RCgcI7b8WkZcZ6RTFivZsiLWwYFCb8OfG8oMewslMlq1g+L6wJIsy VJ2GnLzscIpngwyoFwyid7w86koVC8/ki3Xe/7Xn640jvFVLPeM/Hso+R4x3WrjX x6v44FSvejqS2wrqnLPt =QfK5 -----END PGP SIGNATURE----- _______________________________________________ Snort-sigs mailing list [email protected] https://lists.snort.org/mailman/listinfo/snort-sigs Please visit http://blog.snort.org for the latest news about Snort! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a href=" https://snort.org/downloads/#rule-downloads">emerging threats</a>!