Snort Subscriber Rules Update 2026-06-09
Research via Snort-sigs <[email protected]> Tue, 9 Jun 2026 20:55:40 +0000 (GMT)
| Newsgroups | gmane.comp.security.ids.snort.sigs |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Talos Snort Subscriber Rules Update Synopsis: Talos is aware of vulnerabilities affecting products from Microsoft Corporation. Details: Microsoft Vulnerability CVE-2020-17103: A coding deficiency exists in Microsoft Windows Cloud Files Mini Filter Driver that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66607 through 66608, Snort 3: GID 1, SID 301534. Microsoft Vulnerability CVE-2026-41091: A coding deficiency exists in Microsoft Defender that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66605 through 66606, Snort 3: GID 1, SID 301533. Microsoft Vulnerability CVE-2026-42905: A coding deficiency exists in Microsoft Windows DWM Core Library that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66572 through 66573, Snort 3: GID 1, SID 301523. Microsoft Vulnerability CVE-2026-42980: A coding deficiency exists in Microsoft NT OS Kernel that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66594 through 66595, Snort 3: GID 1, SID 301529. Microsoft Vulnerability CVE-2026-42985: A coding deficiency exists in Microsoft Remote Desktop Client that may lead to remote code execution. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SID 66581, Snort 3: GID 1, SID 66581. Microsoft Vulnerability CVE-2026-42986: A coding deficiency exists in Microsoft Graphics Component that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66574 through 66575, Snort 3: GID 1, SID 301524. Microsoft Vulnerability CVE-2026-42989: A coding deficiency exists in Microsoft Winlogon that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66576 through 66577, Snort 3: GID 1, SID 301525. Microsoft Vulnerability CVE-2026-44803: A coding deficiency exists in Microsoft Windows Graphics Component that may lead to remote code execution. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66589 through 66590, Snort 3: GID 1, SID 301527. Microsoft Vulnerability CVE-2026-44812: A coding deficiency exists in Microsoft Windows Graphics Component that may lead to remote code execution. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66603 through 66604, Snort 3: GID 1, SID 301532. Microsoft Vulnerability CVE-2026-45586: A coding deficiency exists in Microsoft Windows Collaborative Translation Framework (CTFMON) that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66601 through 66602, Snort 3: GID 1, SID 301531. Microsoft Vulnerability CVE-2026-45658: A coding deficiency exists in Microsoft Windows BitLocker that may lead to security feature bypass. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66609 through 66610, Snort 3: GID 1, SID 301535. Microsoft Vulnerability CVE-2026-47291: A coding deficiency exists in Microsoft HTTP.sys that may lead to remote code execution. A rule to detect attacks targeting this vulnerability is included in this release and is identified with: Snort 2: GID 1, SID , Snort 3: GID 1, SID 301528. Talos has added and modified multiple rules in the malware-cnc, os-linux, os-windows, protocol-rpc, server-mail and server-webapp rule sets to provide coverage for emerging threats from these technologies. For a complete list of new and modified rules please see: https://www.snort.org/advisories -----BEGIN PGP SIGNATURE----- iQIcBAEBAgAGBQJqKH3MAAoJEHB/DbSAg2dx/uwP/0NHH0F2uiRhyM6pmanU51KU xwnY8wnjZhETEArhpmj0dF2rtWVOg5k3u2qEaW/0Ecfv6yeCjyTuJDxVjx/vNOd2 K2kwJCj5+SPszgmHjTZu3KbM9Du4dN/ZnrpfbjzQ/+3XQyvyjhHQFeFvKclP4sfo sfhNaaWdtHJ//fWOxqSD3Qg+lVbzTt8/qXXY9LlORbHEd7HPpd2sWasfDNdW7eO0 oN/Og4j+nROpP6V9+z5zo35pd45lHN021zet97bxODFG70jDkqPxMp76oDaWVfZp NVO09leF7L0wwrxcppIm0QVD802AcmqL+QMqkj2KBiGhfBZgXcSih0fPZSDtz+Wm 7bPK9jn7TpQDH5CHm+LxKLu8BjO5pQzS+1mDlodRnXmxnsY76porkFZKWJ5q+bLC S+qVkYXlhSzy8l/7Val7uoqUUdZssymzxxog5xRrjMUkrgIGkK86d4gtoo1yge2X 4vpainuJFldr1Q6rQL9WJcYYVpAaXQMYWfQSSvvyRWXCqzXZQWhnolUsjH726cmn LscMudLlX6sJED+9wKQ4BqsKg4iMeWxDGoHNh2ssM8y/7MK9yB1a8IUCuWPw6Tz3 Hrx69/4QwebXUoanzXrMxn0oKbyyWeo+wtMUfeGLYAth9duPUe6xeQn3i5eGVGXU NSijhh2kZrntp6TxjhMu =7er+ -----END PGP SIGNATURE----- _______________________________________________ Snort-sigs mailing list [email protected] https://lists.snort.org/mailman/listinfo/snort-sigs Please visit http://blog.snort.org for the latest news about Snort! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a href=" https://snort.org/downloads/#rule-downloads">emerging threats</a>!