Snort Subscriber Rules Update 2026-03-10

Research via Snort-sigs <[email protected]> Tue, 10 Mar 2026 22:19:03 +0000 (GMT)
Newsgroups gmane.comp.security.ids.snort.sigs
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


Talos Snort Subscriber Rules Update

Synopsis:
Talos is aware of vulnerabilities affecting products from Microsoft
Corporation.

Details:
Microsoft Vulnerability CVE-2026-23668:
A coding deficiency exists in Microsoft Windows Graphics Component that
may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 66091 through 66092,
Snort 3: GID 1, SID 301443.

Microsoft Vulnerability CVE-2026-24289:
A coding deficiency exists in Microsoft Windows Kernel that may lead to
an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 66089 through 66090,
Snort 3: GID 1, SID 301442.

Microsoft Vulnerability CVE-2026-24291:
A coding deficiency exists in Microsoft Windows Accessibility
Infrastructure (ATBroker.exe) that may lead to an escalation of
privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 66101 through 66102,
Snort 3: GID 1, SID 301445.

Microsoft Vulnerability CVE-2026-25187:
A coding deficiency exists in Microsoft Winlogon that may lead to an
escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 66096 through 66097,
Snort 3: GID 1, SID 301444.

Microsoft Vulnerability CVE-2026-26132:
A coding deficiency exists in Microsoft Windows Kernel that may lead to
an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 66103 through 66104,
Snort 3: GID 1, SID 301446.

Talos has added and modified multiple rules in the file-image,
file-other, os-windows, policy-other and server-webapp rule sets to
provide coverage for emerging threats from these technologies.


For a complete list of new and modified rules please see:

https://www.snort.org/advisories
-----BEGIN PGP SIGNATURE-----

iQIcBAEBAgAGBQJpsJjWAAoJEHB/DbSAg2dxgzMP+gKtVp/zR/uj2IpUe57MKIpp
cbpiVyKafN6p8Jx/Ta9DRwNm9ii8mxjACYerjuUD1N9x+XDKJtlD+PGVcPI7Zxfz
LFsiIeJcQjj/LEkEcbNae7ySbS3OSj6+90fT0nL1mAL8+NLyTY9ovpVB1dqsl0Xu
j8IJoKCKNnejx29GNLpVSbXJZn7t+Lo9OWc0CNmTLfp0mz54iAjpRa5NBSyxTTvn
4+4Nq4iDBeRbTNMpOxMbVBTFjCkApNFdXoviOgSJJ72BhxvC9d6DiIz3XSLvDtXw
nYMcb4URkHTiBlmnb6O3/czk7qFNukAFfYblvHRhA4K4ceJKu7XOa5ggIqWwOwRA
Pk2X7SAM5hekkj1lG8TubyCDhl9Fu48psH26kBJslYQLVe7wWL5+srChzt8RcJDt
G/wUsO7wcMW+sgmHZoOE4TCc6BW2E9hkUlJKE37HI2lF5/geV9V9RmMH0JalTblW
BWH00ZS09ZFrklVVN8X6kGtJIYasmE18DhdhgJHw6gNPmU1OheA4FyLIpBJq3cP/
j5KgDeRb8neV+BlZGdxsYRI7yn/77kK9VYAH91CCmr4OtNldR3L0qJRt+Kcg1rvE
Yp1pQfFZuxG2zOETv5eQke16mx1CGMmKbhUv0Yuj98ZTnvjB4zLBbC6RxanxA0rm
/rhKOGjOdu1tOlbxp93N
=uo2L
-----END PGP SIGNATURE-----

_______________________________________________
Snort-sigs mailing list
[email protected]
https://lists.snort.org/mailman/listinfo/snort-sigs

Please visit http://blog.snort.org for the latest news about Snort!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a href=" https://snort.org/downloads/#rule-downloads">emerging threats</a>!