Snort Subscriber Rules Update 2026-06-09

Research via Snort-sigs <[email protected]> Tue, 9 Jun 2026 20:55:40 +0000 (GMT)
Newsgroups gmane.comp.security.ids.snort.sigs
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


Talos Snort Subscriber Rules Update

Synopsis:
Talos is aware of vulnerabilities affecting products from Microsoft
Corporation.

Details:
Microsoft Vulnerability CVE-2020-17103:
A coding deficiency exists in Microsoft Windows Cloud Files Mini Filter
Driver that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 66607 through 66608,
Snort 3: GID 1, SID 301534.

Microsoft Vulnerability CVE-2026-41091:
A coding deficiency exists in Microsoft Defender that may lead to an
escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 66605 through 66606,
Snort 3: GID 1, SID 301533.

Microsoft Vulnerability CVE-2026-42905:
A coding deficiency exists in Microsoft Windows DWM Core Library that
may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 66572 through 66573,
Snort 3: GID 1, SID 301523.

Microsoft Vulnerability CVE-2026-42980:
A coding deficiency exists in Microsoft NT OS Kernel that may lead to
an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 66594 through 66595,
Snort 3: GID 1, SID 301529.

Microsoft Vulnerability CVE-2026-42985:
A coding deficiency exists in Microsoft Remote Desktop Client that may
lead to remote code execution.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SID 66581,
Snort 3: GID 1, SID 66581.

Microsoft Vulnerability CVE-2026-42986:
A coding deficiency exists in Microsoft Graphics Component that may
lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 66574 through 66575,
Snort 3: GID 1, SID 301524.

Microsoft Vulnerability CVE-2026-42989:
A coding deficiency exists in Microsoft Winlogon that may lead to an
escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 66576 through 66577,
Snort 3: GID 1, SID 301525.

Microsoft Vulnerability CVE-2026-44803:
A coding deficiency exists in Microsoft Windows Graphics Component that
may lead to remote code execution.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 66589 through 66590,
Snort 3: GID 1, SID 301527.

Microsoft Vulnerability CVE-2026-44812:
A coding deficiency exists in Microsoft Windows Graphics Component that
may lead to remote code execution.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 66603 through 66604,
Snort 3: GID 1, SID 301532.

Microsoft Vulnerability CVE-2026-45586:
A coding deficiency exists in Microsoft Windows Collaborative
Translation Framework (CTFMON) that may lead to an escalation of
privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 66601 through 66602,
Snort 3: GID 1, SID 301531.

Microsoft Vulnerability CVE-2026-45658:
A coding deficiency exists in Microsoft Windows BitLocker that may lead
to security feature bypass.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 66609 through 66610,
Snort 3: GID 1, SID 301535.

Microsoft Vulnerability CVE-2026-47291:
A coding deficiency exists in Microsoft HTTP.sys that may lead to
remote code execution.

A rule to detect attacks targeting this vulnerability is included in
this release and is identified with:
Snort 2: GID 1, SID ,
Snort 3: GID 1, SID 301528.

Talos has added and modified multiple rules in the malware-cnc,
os-linux, os-windows, protocol-rpc, server-mail and server-webapp rule
sets to provide coverage for emerging threats from these technologies.


For a complete list of new and modified rules please see:

https://www.snort.org/advisories
-----BEGIN PGP SIGNATURE-----

iQIcBAEBAgAGBQJqKH3MAAoJEHB/DbSAg2dx/uwP/0NHH0F2uiRhyM6pmanU51KU
xwnY8wnjZhETEArhpmj0dF2rtWVOg5k3u2qEaW/0Ecfv6yeCjyTuJDxVjx/vNOd2
K2kwJCj5+SPszgmHjTZu3KbM9Du4dN/ZnrpfbjzQ/+3XQyvyjhHQFeFvKclP4sfo
sfhNaaWdtHJ//fWOxqSD3Qg+lVbzTt8/qXXY9LlORbHEd7HPpd2sWasfDNdW7eO0
oN/Og4j+nROpP6V9+z5zo35pd45lHN021zet97bxODFG70jDkqPxMp76oDaWVfZp
NVO09leF7L0wwrxcppIm0QVD802AcmqL+QMqkj2KBiGhfBZgXcSih0fPZSDtz+Wm
7bPK9jn7TpQDH5CHm+LxKLu8BjO5pQzS+1mDlodRnXmxnsY76porkFZKWJ5q+bLC
S+qVkYXlhSzy8l/7Val7uoqUUdZssymzxxog5xRrjMUkrgIGkK86d4gtoo1yge2X
4vpainuJFldr1Q6rQL9WJcYYVpAaXQMYWfQSSvvyRWXCqzXZQWhnolUsjH726cmn
LscMudLlX6sJED+9wKQ4BqsKg4iMeWxDGoHNh2ssM8y/7MK9yB1a8IUCuWPw6Tz3
Hrx69/4QwebXUoanzXrMxn0oKbyyWeo+wtMUfeGLYAth9duPUe6xeQn3i5eGVGXU
NSijhh2kZrntp6TxjhMu
=7er+
-----END PGP SIGNATURE-----

_______________________________________________
Snort-sigs mailing list
[email protected]
https://lists.snort.org/mailman/listinfo/snort-sigs

Please visit http://blog.snort.org for the latest news about Snort!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a href=" https://snort.org/downloads/#rule-downloads">emerging threats</a>!