Snort Subscriber Rules Update 2025-12-09

Research via Snort-sigs <[email protected]> Tue, 9 Dec 2025 23:26:35 +0000 (GMT)
Newsgroups gmane.comp.security.ids.snort.sigs
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


Talos Snort Subscriber Rules Update

Synopsis:
Talos is aware of vulnerabilities affecting products from Microsoft
Corporation.

Details:

Microsoft Vulnerability CVE-2025-59516:
A coding deficiency exists in Microsoft Windows Storage VSP Driver that
may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 65557 through 65558,
Snort 3: GID 1, SID 301352.

Microsoft Vulnerability CVE-2025-59517:
A coding deficiency exists in Microsoft Windows Storage VSP Driver that
may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 65559 through 65560,
Snort 3: GID 1, SID 301353.

Microsoft Vulnerability CVE-2025-62221:
A coding deficiency exists in Microsoft Windows Cloud Files Mini Filter
Driver that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 65571 through 65572,
Snort 3: GID 1, SID 301356.

Microsoft Vulnerability CVE-2025-62454:
A coding deficiency exists in Microsoft Windows Cloud Files Mini Filter
Driver that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 65573 through 65574,
Snort 3: GID 1, SID 301357.

Microsoft Vulnerability CVE-2025-62458:
A coding deficiency exists in Microsoft Win32k that may lead to an
escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 62486 through 62487,
Snort 3: GID 1, SID 300719.

Microsoft Vulnerability CVE-2025-62470:
A coding deficiency exists in Microsoft Windows Common Log File System
Driver that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 65555 through 65556,
Snort 3: GID 1, SID 301351.

Microsoft Vulnerability CVE-2025-62472:
A coding deficiency exists in Microsoft Windows Remote Access
Connection Manager that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 65561 through 65562,
Snort 3: GID 1, SID 301354.

Talos has added and modified multiple rules in the file-other,
malware-cnc, malware-other, os-windows and server-webapp rule sets to
provide coverage for emerging threats from these technologies.


For a complete list of new and modified rules please see:

https://www.snort.org/advisories
-----BEGIN PGP SIGNATURE-----

iQIcBAEBAgAGBQJpOLAqAAoJEHB/DbSAg2dxlZgQAKy9JWbM4PGhGfLh+dgQRq5G
ltZDFNZ7zvLHWvs/fQQTTgsusyA5xJwp/cevyUeGD4orTlo6wiwwmysV1i4vFo1b
1xhVM+v/BJDHD3LCi2eYIQ/3m3RXqODZTVo9CPKeNuKIigGlsrpT4MuuwbJ0bLcK
2KB1IMgXNzVcLVe3zrK5Ju9bFE/mG2b1lq3qBVXUG14WFu0zdd2T0eURPzCA2JJH
kNi++sn4Gd12dFql3sIpRVzIRjuw7ai0UCLLYh6frYesSCiOKXozQpN5yjro7ILM
TntfmC09ZSjfjw9rAuG7XVitDXylRdOsHc8d5SmWE2lK/3o8MSIKPwa0GCqOCPAN
fOx6ceTDUjdIcOnXbXEVJMitRuchzVfk0LOgvW343SCVFHcbmw81BLmOzUeHZIWX
OYBvRA91OwEXiTc2PC/52Cb7BgJN/Flg77ucKDQAoQH/HebOgRYJDoZ+CJMaKhBc
bgHMoOiERQRTG+1UpGFuNGtYjohsJikwEojABpbunK+uRM9DC7fd3+l5WS5Dkd4L
TCyt/W8JCM/RCgcI7b8WkZcZ6RTFivZsiLWwYFCb8OfG8oMewslMlq1g+L6wJIsy
VJ2GnLzscIpngwyoFwyid7w86koVC8/ki3Xe/7Xn640jvFVLPeM/Hso+R4x3WrjX
x6v44FSvejqS2wrqnLPt
=QfK5
-----END PGP SIGNATURE-----

_______________________________________________
Snort-sigs mailing list
[email protected]
https://lists.snort.org/mailman/listinfo/snort-sigs

Please visit http://blog.snort.org for the latest news about Snort!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a href=" https://snort.org/downloads/#rule-downloads">emerging threats</a>!