Snort Subscriber Rules Update 2026-05-12
Research via Snort-sigs <[email protected]> Tue, 12 May 2026 19:28:55 +0000 (GMT)
| Newsgroups | gmane.comp.security.ids.snort.sigs |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Talos Snort Subscriber Rules Update Synopsis: Talos is aware of vulnerabilities affecting products from Microsoft Corporation. Details: Microsoft Vulnerability CVE-2026-33835: A coding deficiency exists in Microsoft Windows Cloud Files Mini Filter Driver that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66438 through 66439, Snort 3: GID 1, SID 301494. Microsoft Vulnerability CVE-2026-33837: A coding deficiency exists in Microsoft Windows TCP/IP Local that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66440 through 66441, Snort 3: GID 1, SID 301495. Microsoft Vulnerability CVE-2026-33840: A coding deficiency exists in Microsoft Win32k that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66442 through 66443, Snort 3: GID 1, SID 301496. Microsoft Vulnerability CVE-2026-33841: A coding deficiency exists in Microsoft Windows Kernel that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66453 through 66454, Snort 3: GID 1, SID 301501. Microsoft Vulnerability CVE-2026-35416: A coding deficiency exists in Microsoft Windows Ancillary Function Driver for WinSock that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66455 through 66456, Snort 3: GID 1, SID 301502. Microsoft Vulnerability CVE-2026-35417: A coding deficiency exists in Microsoft Windows Win32k that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66459 through 66460, Snort 3: GID 1, SID 301504. Microsoft Vulnerability CVE-2026-40361: A coding deficiency exists in Microsoft Word that may lead to remote code execution. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66457 through 66458, Snort 3: GID 1, SID 301503. Microsoft Vulnerability CVE-2026-40364: A coding deficiency exists in Microsoft Word that may lead to remote code execution. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66474 through 66475, Snort 3: GID 1, SID 301506. Microsoft Vulnerability CVE-2026-40369: A coding deficiency exists in Microsoft Windows Kernel that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66444 through 66445, Snort 3: GID 1, SID 301497. Microsoft Vulnerability CVE-2026-40397: A coding deficiency exists in Microsoft Windows Common Log File System Driver that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66470 through 66471, Snort 3: GID 1, SID 301505. Microsoft Vulnerability CVE-2026-40398: A coding deficiency exists in Microsoft Windows Remote Desktop Services that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66451 through 66452, Snort 3: GID 1, SID 301500. Microsoft Vulnerability CVE-2026-41089: A coding deficiency exists in Microsoft Windows Netlogon that may lead to remote code execution. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SID 66476, Snort 3: GID 1, SID 66476. Microsoft Vulnerability CVE-2026-41103: A coding deficiency exists in Microsoft SSO Plugin for Jira & Confluence that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66472 through 66473, Snort 3: GID 1, SIDs 66472 through 66473. Talos has added and modified multiple rules in the browser-chrome, browser-firefox, file-office, os-windows, policy-other and server-webapp rule sets to provide coverage for emerging threats from these technologies. For a complete list of new and modified rules please see: https://www.snort.org/advisories -----BEGIN PGP SIGNATURE----- iQIcBAEBAgAGBQJqA392AAoJEHB/DbSAg2dxNh4P/j2/CDx+Ut9Si9KBgYZyQaDo Tri7yOF5wsit7od/JjZ6QFqLdJYcEzKJTZIGH9HmHAi9nriJIn2Y8f36oxTP+3x7 9RAb/lEy1/ss0fVvnUO+czkb2bvsL9r/LvQBKh5Um41+1qc6IHRigw1tvfMk06Ps CQMKKqtXgJgtJerS8MsmIH9DC6hKUOGGPrANID8gL51NKSlWxuiavckFCpQziIMX 4eIeF9DZHSwZtclnVVQrZ88x7tksAAeFliBUFYsvGEY0/hArTN5xfMqyn1DXDg0x MoKVF9xdVfCMVBvK2C4zgbRel+zJEnBKgWdR4ojEuKzuqcRkuPnUHP2L6BFDwiDP c7MWZQqbHtFxLYuH0dSvKBr5YKyy8sfhd+nFVUnPoWvP4G3SxieL60LgR2+CDbyK KiK4jvqPMC7j2XdKgy9zd82fY5ix5NultRqCsLrjWKhkslDcDZI2uHXxqeYsQZ6U IIMrty0nZ3gNjMRzNrNijeVSQUYhUBb0jyiN8/8c4SOrhSbje1MvUTNqujbRNU82 3GOyVgdVR0+lu5bZexlJbcVtJ8/vKrNBauwS4oUXsHOovsKPZpR+CCHCm01pdCbf Rh9TxHqW5RAdxbEus8L9uk3ug1/Xdi90U7x5Y0kYAzHXeQNAre/TWg6YsWxFqd+H S6ti9S+g7w/B1tXamhBf =pibB -----END PGP SIGNATURE----- _______________________________________________ Snort-sigs mailing list [email protected] https://lists.snort.org/mailman/listinfo/snort-sigs Please visit http://blog.snort.org for the latest news about Snort! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a href=" https://snort.org/downloads/#rule-downloads">emerging threats</a>!