Snort Subscriber Rules Update 2026-08-11
Research via Snort-sigs <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.sigs |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Talos Snort Subscriber Rules Update Synopsis: Talos is aware of vulnerabilities affecting products from Microsoft Corporation. Details: Microsoft Vulnerability CVE-2026-61348: A coding deficiency exists in Microsoft Windows Ancillary Function Driver for WinSock that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66903 through 66904, Snort 3: GID 1, SID 301589. Microsoft Vulnerability CVE-2026-61358: A coding deficiency exists in Microsoft Windows Accessibility Infrastructure (ATBroker.exe) that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66905 through 66906, Snort 3: GID 1, SID 301590. Microsoft Vulnerability CVE-2026-61359: A coding deficiency exists in Microsoft Windows Storage that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66943 through 66944, Snort 3: GID 1, SID 301605. Microsoft Vulnerability CVE-2026-61929: A coding deficiency exists in Microsoft Windows Kernel that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66914 through 66915, Snort 3: GID 1, SID 301594. Microsoft Vulnerability CVE-2026-61930: A coding deficiency exists in Microsoft Windows Kernel that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66916 through 66917, Snort 3: GID 1, SID 301595. Microsoft Vulnerability CVE-2026-62688: A coding deficiency exists in Microsoft Windows MIDI Service Module Elevation of Privileges Vulnerability that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66939 through 66940, Snort 3: GID 1, SID 301603. Microsoft Vulnerability CVE-2026-62696: A coding deficiency exists in Microsoft Windows Program Compatibility Assistant Service that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66918 through 66919, Snort 3: GID 1, SID 301596. Microsoft Vulnerability CVE-2026-62698: A coding deficiency exists in Microsoft Digest Authentication that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66941 through 66942, Snort 3: GID 1, SID 301604. Microsoft Vulnerability CVE-2026-62712: A coding deficiency exists in Microsoft Windows Win32k that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66937 through 66938, Snort 3: GID 1, SID 301602. Microsoft Vulnerability CVE-2026-62713: A coding deficiency exists in Microsoft Windows Cloud Files Mini Filter Driver that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66907 through 66908, Snort 3: GID 1, SID 301591. Microsoft Vulnerability CVE-2026-62721: A coding deficiency exists in Microsoft Windows User-Mode Power Service (UMPS) that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66929 through 66930, Snort 3: GID 1, SID 301599. Microsoft Vulnerability CVE-2026-62735: A coding deficiency exists in Microsoft Windows HTTP.sys that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66931 through 66932, Snort 3: GID 1, SID 301600. Microsoft Vulnerability CVE-2026-62737: A coding deficiency exists in Microsoft Windows Kernel that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66909 through 66910, Snort 3: GID 1, SID 301592. Microsoft Vulnerability CVE-2026-62766: A coding deficiency exists in Microsoft Windows Kerberos that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66912 through 66913, Snort 3: GID 1, SID 301593. Microsoft Vulnerability CVE-2026-62783: A coding deficiency exists in Microsoft Windows Remote Access Connection Manager that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66920 through 66921, Snort 3: GID 1, SID 301597. Microsoft Vulnerability CVE-2026-62788: A coding deficiency exists in Microsoft Windows Kernel that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66935 through 66936, Snort 3: GID 1, SID 301601. Microsoft Vulnerability CVE-2026-62893: A coding deficiency exists in Microsoft Windows Deployment Services TFTP Server that may lead to remote code execution. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SID 66902, Snort 3: GID 1, SID 66902. Microsoft Vulnerability CVE-2026-65775: A coding deficiency exists in Microsoft Windows Win32k that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66922 through 66923, Snort 3: GID 1, SID 301598. Microsoft Vulnerability CVE-2026-65788: A coding deficiency exists in Microsoft Desktop Window Manager that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66947 through 66948, Snort 3: GID 1, SID 301607. Microsoft Vulnerability CVE-2026-68820: A coding deficiency exists in Microsoft Windows Ancillary Function Driver for WinSock that may lead to an escalation of privilege. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66945 through 66946, Snort 3: GID 1, SID 301606. Talos also has added and modified multiple rules in the file-other, malware-cnc, os-windows and server-webapp rule sets to provide coverage for emerging threats from these technologies. For a complete list of new and modified rules please see: https://www.snort.org/advisories -----BEGIN PGP SIGNATURE----- iQIcBAEBAgAGBQJqe58LAAoJEHB/DbSAg2dxGcYP/jK/koV0/Ijwcbp3jNR+l/AN LYi83Vak4UekAwscaXVR3U5wouNxteUXioxegj1yDKvyM1an0U+2qEvzb9xQeSLC 0Eme6l6u+0cCUjYdl8ORE3SABVI4Ilq/KeSJKdsb7T3j7u2dL+qt6CLx9+V6FFGZ q7u/Utrc1aRRzzRh669d8d2Yd5MxkwPppedLet3hkfL5oz810mSpLTu89YXCErNL a8E5c2ObtVgl8IEqsegggpGcrLz0w32OZzyGDxJ3lRjl4ReZ2LAwgrsXTe0udIh/ S6Uh2fJGQPpgz6KDnD/0fobsNJNqcxj4UeQEdy9QV8+q2kdeKYiToMlcAPZKMEwl NLcjVI5noMZeTH1x/p6nvr7QSWTYokSZNNLEr58Xe71H8QLahc5ToKVV6KnAyCNA H62X297B7SAfI3secOFIT5DT0LlOOCatZykwUp1Zco/bShpfZIZ4DBdAkLzoaMli hmpUh0C/9w0ZrnMTHVfhNap2SMOYymQsXaBTmSc7h5wwKiisJkU0yVGQPguviCQZ UitNQcmJGJwmLmpNptDhusujjXPCS22zYFFMP5IMWc0pc/6llDNDqsKZF+i9SrAz t0O+cZFi8A2hE92AZEfZkWSGB4U9QwFnMbptLZKxQ8pY4PmzcVH0WGO9a0hvjnVW iSZfl2OLBAfAFDKcy5Ps =W3+1 -----END PGP SIGNATURE----- _______________________________________________ Snort-sigs mailing list [email protected] https://lists.snort.org/mailman/listinfo/snort-sigs Please visit http://blog.snort.org for the latest news about Snort! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a href=" https://snort.org/downloads/#rule-downloads">emerging threats</a>!