The latest SNORT® rule release from Cisco Talos has arrived. This new round of rules provides coverage for all of the vulnerabilities covered in Microsoft Patch Tuesday.
For more details on the vulnerabilities Microsoft disclosed this week, head to the Talos blog.
In all, this release includes 89 new rules, seven modified rules and three shared object rules.
For more details on the vulnerabilities Microsoft disclosed this week, head to the Talos blog.
In all, this release includes 89 new rules, seven modified rules and three shared object rules.
There were no changes made to the
snort.conf
in this release.Talos's rule release:
Microsoft Vulnerability CVE-2019-1390: A coding deficiency exists in Microsoft Windows VBScript Engine that may lead to remote code execution.You can subscribe to Talos' newest rule detection functionality for as low as $29 a year with a personal account. Be sure and see our business pricing as well here. Make sure and stay up to date to catch the most emerging threats.
Previously released rules will detect attacks targeting these vulnerabilities and have been updated with the appropriate reference information. They are also included in this release and are identified with GID 1, SIDs 46548 through 46549.
Microsoft Vulnerability CVE-2019-1393: A coding deficiency exists in Microsoft Win32k that may lead to an escalation of privilege.
Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with GID 1, SIDs 52205 through 52208.
Microsoft Vulnerability CVE-2019-1394: A coding deficiency exists in Microsoft Win32k that may lead to an escalation of privilege.
Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with GID 1, SIDs 52209 through 52212.
Microsoft Vulnerability CVE-2019-1395: A coding deficiency exists in Microsoft Win32k that may lead to an escalation of privilege.
Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with GID 1, SIDs 52217 through 52220.
Microsoft Vulnerability CVE-2019-1396: A coding deficiency exists in Microsoft Win32k that may lead to an escalation of privilege.
Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with GID 1, SIDs 52213 through 52216.
Microsoft Vulnerability CVE-2019-1408: A coding deficiency exists in Microsoft Win32k that may lead to an escalation of privilege.
Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with GID 1, SIDs 52225 through 52228.
Microsoft Vulnerability CVE-2019-1429: A coding deficiency exists in Microsoft Scripting Engine that may lead to remote code execution.
Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with GID 1, SIDs 52239 through 52240.
Microsoft Vulnerability CVE-2019-1435: A coding deficiency exists in Microsoft Graphics Component that may lead to an escalation of privilege.
Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with GID 1, SIDs 52229 through 52232.
Microsoft Vulnerability CVE-2019-1436: A coding deficiency exists in Microsoft Scripting Engine that may lead to information disclosure.
Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with GID 1, SIDs 52233 through 52234.
Microsoft Vulnerability CVE-2019-1437: A coding deficiency exists in Microsoft Graphics Component that may lead to an escalation of privilege.
Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with GID 1, SIDs 52223 through 52224.
Microsoft Vulnerability CVE-2019-1438: A coding deficiency exists in Microsoft Graphics Component that may lead to an escalation of privilege.
Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with GID 1, SIDs 52221 through 52222.
Talos also has added and modified multiple rules in the browser-firefox, browser-ie, malware-cnc, os-mobile, os-windows, policy-other, protocol-scada and server-webapp rule sets to provide coverage for emerging threats from these technologies.