Showing posts with label adobe. Show all posts
Showing posts with label adobe. Show all posts

Tuesday, February 26, 2019

Snort rule update for Feb. 26, 2019

Just released:
Snort Subscriber Rule Set Update for Feb. 26, 2019

Cisco Talos just released the newest SNORT® rule set. This release includes 25 new and eight modified rules, none of which are shared object rules.

In this release, we continue to provide coverage for the Adobe Acrobat and Reader vulnerabilities disclosed earlier this month. There's also a rule protecting users against a recent critical vulnerability discovered in the Drupal project that could allow an attacker to gain remote code execution privileges.

Tuesday, February 19, 2019

Snort rule update for Feb. 19, 2019

Just released:
Snort Subscriber Rule Set Update for Feb. 19, 2019

Cisco Talos just released the newest SNORT® rule set. This release includes 26 new rules and six modified rules, none of which are shared object rules.

In this release, we provide additional coverage for the slew of vulnerabilities Adobe disclosed last week, as well as protection against the Keymarble malware.

Friday, November 9, 2018

Critical Snort rule update for Adobe ColdFusion

Just released:
Snort Subscriber Rule Set Update for Nov. 9, 2018

Cisco Talos just released a critical SNORTⓇ rule release2. that provides coverage for a vulnerability in Adobe ColdFusion. Attackers are targeting unpatched versions of the web development platform by exploiting CVE-2018-15961.

Tuesday, November 21, 2017

Snort Subscriber Rule Set Update for 11/21/2017, Adobe Vulns

Just released:
Snort Subscriber Rule Set Update for 11/21/2017


We welcome the introduction of the newest rule release from Talos. In this release we introduced 105 new rules of which 4 are Shared Object rules and made modifications to 18 additional rules of which 0 are Shared Object rules.

There were no changes made to the snort.conf in this release.


Talos's rule release:
Talos has added and modified multiple rules in the blacklist, browser-firefox, browser-ie, file-flash, file-image, file-office, file-other, file-pdf, malware-cnc, malware-other and server-webapp rule sets to provide coverage for emerging threats from these technologies.


In order to subscribe now to Talos's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at https://snort.org/products#rule_subscriptions. Make sure and stay up to date to catch the most emerging threats!

Wednesday, October 12, 2016

Snort Subscriber Rule Set Update for 10/11/2016, Release Two

Just released:
Snort Subscriber Rule Set Update for 10/11/2016, Release two


We welcome the introduction of the newest rule release from Talos. In this release we introduced 13 new rules and made modifications to 2 additional rules.

There were no changes made to the snort.conf in this release.

Talos's rule release:
Talos has added and modified multiple rules in the exploit-kit, file-flash and malware-cnc rule sets to provide coverage for emerging threats from these technologies.


In order to subscribe now to Talos's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at https://www.snort.org/products. Make sure and stay up to date to catch the most emerging threats!

Tuesday, March 15, 2016

Snort Subscriber Rule Set Update for 03/15/2016

Just released:
Snort Subscriber Rule Set Update for 03/15/2016

We welcome the introduction of the newest rule release from Talos. In this release we introduced 20 new rules and made modifications to 30 additional rules.

There were no changes made to the snort.conf in this release.



Talos's rule release:
CVE 2016-1010: Adobe Flash Player suffers from programming errors that may lead to remote code execution. Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with GID 1, SIDs 38238 through 38241. 
Talos has also added and modified multiple rules in the blacklist, browser-plugins, exploit-kit, file-flash, file-office, file-other, malware-cnc and server-webapp rule sets to provide coverage for emerging threats from these technologies.

In order to subscribe now to Talos's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at https://www.snort.org/products. Make sure and stay up to date to catch the most emerging threats!

Wednesday, June 24, 2015

Snort Subscriber Rule Set Update for 06/24/2015, Adobe CVE-2015-3113

Just released:
Snort Subscriber Rule Set Update for 06/24/2015


We welcome the introduction of the newest rule release from Talos. In this release we introduced 20 new rules and made modifications to 8 additional rules.

There were no changes made to the snort.conf in this release.

Talos's rule release:
Adobe Security Bulletin APSB15-14 (CVE-2015-3113):
Adobe Flash Player suffers from programming errors that may lead to remote code
execution.

Rules to detect attacks targeting these vulnerabilities are included in this
release and are identified with GID 1, SIDs 34988 through 34989.

Talos has also added and modified multiple rules in the file-flash,
file-office, file-other, indicator-compromise, malware-cnc, malware-other,
policy-other and server-webapp rule sets to provide coverage for emerging
threats from these technologies.


In order to subscribe now to Talos's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at https://www.snort.org/products. Make sure and stay up to date to catch the most emerging threats!

Tuesday, July 8, 2014

Snort Subscriber Rule Set Update for 07/08/2014

Just released:
Snort Subscriber Rule Set Update for 07/08/2014

We welcome the introduction of the newest rule release from the VRT. In this release we introduced 6 new rules and made modifications to 5 additional rules.

There were no changes made to the snort.conf in this release.

In VRT's rule release:
Synopsis: The VRT is aware of vulnerabilities affecting products from Adobe Systems. 
Details: Adobe Security Bulletin APSB14-17: A coding deficiency exists in Adobe Flash Player that may lead to remote code execution. Rules to detect attacks targeting this vulnerability are included in this release and are identified with GID 1, SIDs 31392 through 31397.


In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Monday, April 28, 2014

Sourcefire VRT Certified Snort Rules Update for 04/28/2014, Adobe Flash 0day

Just released:
Sourcefire VRT Certified Snort Rules Update for 04/28/2014


We welcome the introduction of the newest rule release from the VRT. In this release we introduced 54 new rules and made modifications to 4 additional rules.

There were no changes made to the snort.conf in this release.


In VRT's rule release:
CVE-2014-0515: Adobe Flash Player contains a coding deficiency that may lead to remote code execution. 
A rule to detect attacks targeting this vulnerability is included in this release and is identified with GID 1, SID 30877. 
The Sourcefire VRT has also added and modified multiple rules in the app-detect, blacklist, browser-ie, exploit-kit, file-flash, file-multimedia and protocol-dns rule sets to provide coverage for emerging threats from these technologies.

In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Friday, November 16, 2012

Sourcefire VRT Certified Snort Rules Update for 11/15/2012, Adobe 0day

Just released: Sourcefire VRT Certified Snort Rules Update for 11/15/2012

We welcome the introduction of the newest rule release for today from the VRT. In this release we introduced 53 new rules and made modifications to 7 additional rules.

There were no changes made to the snort.conf in this release.

In VRT's rule release:
The Sourcefire VRT has added and modified multiple rules in the browser-firefox, browser-plugins, file-flash, file-identify, file-image, file-multimedia, file-other, file-pdf, malware-other, policy-other, protocol-voip, rpc, server-apache and server-webapp rule sets to provide coverage for emerging threats from these technologies.


In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Thursday, August 16, 2012

Sourcefire VRT Certified Snort Rules Update for 08/15/2012

Just released:
Sourcefire VRT Certified Snort Rules Update for 08/15/2012


We welcome the introduction of the newest rule release for today from the VRT. In this release we introduced 45 new rules and made modifications to 14 additional rules.


There were no changes made to the snort.conf in this release.


In VRT's rule release:
Synopsis:
This release adds and modifies rules in several categories.

Details:
The Sourcefire VRT has added and modified multiple rules in the
botnet-cnc, deleted, file-identify, file-office, file-other, file-pdf,
smtp, specific-threats, spyware-put, web-activex and web-misc rule sets
to provide coverage for emerging threats from these technologies.



In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Wednesday, September 21, 2011

VRT Rule Update for 09/21/2011

Join us as we welcome the introduction of the newest rule release for today from the VRT. In this release we introduce 4 new rules and make modifications to 1 additional rules.

There were no changes made to the snort.conf in this release.

In VRT's rule release:
The Sourcefire VRT has added and modified multiple rules in the exploit, specific-threats, and web-client rule sets to provide coverage for emerging threats from these technologies.

In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Tuesday, August 9, 2011

VRT Rule Update for 08/09/2011, MS Tuesday, and Adobe Coverage

Join us as we welcome the introduction of the newest rule release for today from the VRT. In this release we introduce 33 new rules and make modifications to 6 additional rules.

There were no changes made to the snort.conf in this release.

In VRT's rule release:
The Sourcefire VRT is aware of vulnerabilities affecting products from Microsoft Corporation and Adobe Inc.

Details:
Microsoft Security Advisory MS11-057:
Microsoft Internet Explorer contains programming errors that may allow a remote attacker to execute code on an affected system.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with GID 1, SIDs 19666 through 19672.

Microsoft Security Advisory MS11-058:
The Microsoft implementation of DNS contains a programming error that may allow a remote attacker to execute code on an affected system.

A rule to detect attacks targeting this vulnerability is included in this release and is identified with GID 1, SID 19677.

Microsoft Security Advisory MS11-059:
The Microsoft Data Access Components (MDAC) contains a programming error that may allow a remote attacker to execute code on an affected system.

Rules to detect attacks targeting this vulnerability are included in this release and are identified with GID 1, SIDs 19673 and 19674.

Microsoft Security Advisory MS11-060:
Microsoft Visio contains programming errors that may allow a remote attacker to execute code on an affected system.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with GID 1, SIDs 19675 and 19676.

Microsoft Security Advisory MS11-061:
Microsoft Remote Desktop Web Access contains a programming error that may allow a remote attacker to execute a cross site scripting attack.

A rule to detect attacks targeting this vulnerability is included in this release and is identified with GID 1, SID 19665.

Microsoft Security Advisory MS11-062:
The Microsoft Remote Access Service NDISTAPI driver contains a programming error that may allow a remote attacker to gain privileges on an affected system.

A rule to detect attacks targeting this vulnerability is included in this release and is identified with GID 1, SID 19679.

Microsoft Security Advisory MS11-063:
The Microsoft Windows Client/Server Run-time Subsytem contains a programming error that may allow a remote attacker to gain privileges on an affected system.

A rule to detect attacks targeting this vulnerability is included in this release and is identified with GID 1, SID 19680.

Microsoft Security Advisory MS11-064:
The Microsoft implementation of the TCP/IP stack contains programming errors that may allow a remote attacker to cause a Denial of Service (DoS) against an affected system.

A rule to detect attacks targeting these vulnerabilities is included in this release and is identified with GID 1, SID 19678.

Additionally, a previously released rule will detect attacks targeting these vulnerabilities and has been updated with the appropriate reference information. It is included in this release and is identified with GID 1, SID 17410.

Microsoft Security Advisory MS11-066:
A programming error in the Microsoft .NET framework may lead to unauthorized information disclosure.

A rule to detect attacks targeting this vulnerability is included in this release and is identified with GID 1, SID 19694.

Microsoft Security Advisory MS11-067:
Microsoft Report Viewer contains a programming error that may lead to unauthorized information disclosure.

A rule to detect attacks targeting this vulnerability is included in this release and is identified with GID 1, SID 19681.

Adobe Security Bulletin APSB11-21:
Adobe Flash Player contains programming errors that may allow a remote attacker to execute code on an affected system.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with GID 1, SIDs 19682 through 19693.

In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Tuesday, June 21, 2011

VRT Rule Update for 06/20/2011, Adobe Flash Player Vulnerabilities

The newest rule release for today from the VRT. In this release we introduce 7 new rules and make modifications to 7 more.

There were no changes made to the snort.conf in this release.

In VRT's rule release:
Adobe Security Bulletin APSB11-18:
Adobe Flash Player contains a programming error that may allow a remote attacker to execute code on an affected system via the use of ActionScript.

Rules to detect attacks targeting this vulnerability are included in this release and are identified with GID 1, SIDs 19262 through 19264.

The Sourcefire VRT has added and modified multiple rules in the ftp, shellcode and web-client rule sets to provide coverage for emerging threats from these technologies.

In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Thursday, June 16, 2011

VRT Rule Update for 06/16/2011, Adobe Flash Player Vulnerabilities

The newest rule release for today from the VRT. In this release we introduce 4 new rules and make modifications to 5 more.

There were no changes made to the snort.conf in this release.

In VRT's rule release:
Adobe Security Bulletin APSB11-18:
Adobe Flash Player contains a programming error that may allow a remote attacker to execute code on an affected system.

A rule to detect attacks targeting this vulnerability is included in this release and is identified with GID 1, SID 19257.

The Sourcefire VRT has also added and modified multiple rules in the exploit, specific-threats and web-client rule sets to provide coverage for emerging threats from these technologies.

In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Tuesday, June 14, 2011

VRT Rule Update for 06/14/2011, MS Tuesday, Adobe Reader, and Acrobat

The newest rule release for today from the VRT. In this release we introduce 77 new rules and make modifications to 9 more.

There were no changes made to the snort.conf in this release.

In VRT's rule release:
Microsoft Security Advisory MS11-037:
The Microsoft implementation of MIME HTML (MHTML) contains programming errors that may allow a remote attacker to execute code on an affected system via a cross-site scripting attack.

A previously released rule will detect attacks targeting this vulnerability and is included in this release with updated reference information, it is identified with GID 1, SID 18335.

Microsoft Security Advisory MS11-038:
Microsoft Windows contains a programming error that may allow a remote attacker to execute code on a vulnerable system. The error occurs when parsing specially crafted WMF data.

A rule to detect attacks targeting this vulnerability is included in this release and is identified with GID 1, SID 19184.

Microsoft Security Advisory MS11-039:
The Microsoft .NET Framework contains a programming error that may allow a remote attacker to execute code on an affected system.

A rule to detect attacks targeting this vulnerability is included in this release and is identified with GID 1, SID 19185.

Microsoft Security Advisory MS11-040:
The TMG Firewall Client contains a programming error that may allow a remote attacker to execute code on an affected system.

A rule to detect attacks targeting this vulnerability is included in this release and is identified with GID 3, SID 19187.

Microsoft Security Advisory MS11-041:
The Adobe Font Driver included in the Microsoft Windows Operating System contains a programming error that may allow a remote attacker to execute code on an affected system via a specially crafted font file.

A rule to detect attacks targeting this vulnerability is included in this release and is identified with GID 1, SID 19188.

Microsoft Security Advisory MS11-042:
The Microsoft Distributed File System (DFS) contains programming errors that may allow a remote attacker to execute code on an affected system.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with GID 1, SIDs 19189 and 19221.

Microsoft Security Advisory MS11-043:
The Microsoft client implementation of the Server Message Block (SMB) protocol contains a programming error that may allow a remote attacker to execute code on an affected system.

A rule to detect attacks targeting this vulnerability is included in this release and is identified with GID 1, SID 19199.

Microsoft Security Advisory MS11-045:
Microsoft Excel contains programming errors that may allow a remote attacker to execute code on an affected system via a specially crafted Excel file.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with GID 1, SIDs 19200, 19222, 19225, 19227 and 19229 through 19232.

Microsoft Security Advisory MS11-046:
The Microsoft Windows Operating System contains a programming error that may allow an attacker to execute code on an affected system.

A rule to detect attacks targeting this vulnerability is included in this release and is identified with GID 3, SID 18691.

Microsoft Security Advisory MS11-048:
The Microsoft implementation of the Server Message Block (SMB) protocol contains a programming error that may allow a remote attacker to execute code on an affected system.

A rule to detect attacks targeting this vulnerability is included in this release and is identified with GID 1, SID 19191.

Microsoft Security Advisory MS11-049:
Microsoft Visual Studio contains a programming error that may allow a remote attacker to retrieve the content of local XML files via the use of a specially crafted XML file.

A rule to detect attacks targeting this vulnerability is included in this release and is identified with GID 1, SID 19234.

Microsoft Security Advisory MS11-050:
Microsoft Internet Explorer contains programming errors that may allow a remote attacker to execute code on an affected system or use a cross-site scripting attack against the user.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with GID 1, SIDs 19235 through 19246.

Additionally, a previously released rule will also detect attacks targeting these vulnerabilities and is included in this release with updated reference information. It is identified with GID 3, SID 17767.

Microsoft Security Advisory MS11-051:
The Microsoft Certification Service contains a programming error that may allow a remote attacker to use a cross-site scripting attack against the client using the service.

A rule to detect attacks targeting this vulnerability is included in this release and is identified with GID 1, SID 19186.

Microsoft Security Advisory MS11-052:
Microsoft Internet Explorer contains a programming error that may allow a remote attacker to execute code on an affected system via the use of specially crafted Vector Markup Language (VML) in a URL.

Rules to detect attacks targeting this vulnerability are included in this release and are identified with GID 1, SIDs 19241 and 19242.

Adobe Security Bulletin APSB11-16:
Adobe Reader and Acrobat contain programming errors that may allow a remote attacker to execute code on an affected system.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with GID 1, SIDs 19247 through 19255.

The Sourcefire VRT has also added and modified multiple rules in the bad-traffic, blacklist, dos, exploit, netbios, oracle, policy, smtp, specific-threats, sql, web-activex and web-misc rule sets to provide coverage for emerging threats from these technologies.

In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Friday, May 13, 2011

VRT Rule Update for 05/12/2011

The newest rule release for today from the VRT. In this release we introduce 16 new rules and make modifications to 6 more.


In VRT's rule release:
Adobe Security Bulletin APSB11-12:
Adobe Flash player contains multiple vulnerabilities that may allow a
remote attacker to execute code on a vulnerable system.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 1, SIDs 18963 through 18971.

In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Tuesday, April 12, 2011

Microsoft Tuesday VRT Rule Update for 04/12/2011 & Adobe 0day coverage

Just released, is a rule release for today from the VRT. In this release we introduce 47 new rules and make modifications to 3 more.

In VRT's rule release:
Microsoft Security Advisory MS11-018:
Microsoft Internet Explorer contains programming errors that may allow
a remote attacker to execute code on an affected system.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 3, SIDs 18646 and 18669
through 18671.

Microsoft Security Advisory MS11-019:
The Microsoft implementation of the Common Internet Filing System
(CIFS) contains programming errors that may allow a remote attacker to
execute code on an affected system.

Previously released rules will detect attacks targeting these
vulnerabilities and are included in this release with updated reference
information, and are identified with GID 3, SID 16631 and GID 1, SID
18462.

Microsoft Security Advisory MS11-020:
The Microsoft implementation of the Common Internet Filing System
(CIFS), specifically the Server Message Block (SMB) portion, contains
programming errors that may allow a remote attacker to execute code on
an affected system.

A rule to detect attacks targeting this vulnerability is included in
this release and is identified with GID 3, SID 18660.

Microsoft Security Advisory MS11-021:
Microsoft Excel contains programming errors that may allow a remote
attacker to execute code on an affected system.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 3, SIDs 18630 through 18634,
18639 through 18641 and 18676.

Microsoft Security Advisory MS11-022:
Microsoft PowerPoint contains programming errors that may allow a
remote attacker to execute code on an affected system.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 3, SIDs 18635 through 18637.

Microsoft Security Advisory MS11-023:
Microsoft Office contains programming errors that may allow a remote
attacker to execute code on an affected system.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 3, SIDs 18638, 18647 and
18650.

Microsoft Security Advisory MS11-024:
The Microsoft Fax Cover Page Editor contains a programming error that
may allow a remote attacker to execute code on an affected system.

A rule to detect attacks targeting this vulnerability is included in
this release and is identified with GID 3, SID 18673.

Microsoft Security Advisory MS11-025:
The Microsoft Foundation Class Library (MFC) contains programming
errors that may allow a remote attacker to execute code on an affected
system via applications compiled using these libraries.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 3, SIDs 18619 through 18629.

Microsoft Security Advisory MS11-026:
The Microsoft implementation of MIME HTML (MHTML) contains programming
errors that may allow a remote attacker to execute code on an affected
system via a cross-site scripting attack.

A previously released rule will detect attacks targeting this
vulnerability and is included in this release with updated reference
information, it is identified with GID 1, SID 18335.

Microsoft Security Advisory MS11-027:
Microsoft Internet Explorer, when using ActiveX controls, contains
programming errors that may allow a remote attacker to execute code on
an affected system.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 3, SIDs 18668 and 18672.

Additionally, previously released rules will detect attacks targeting
these vulnerabilities and are included in this release with updated
reference information; they are identified with GID 1, SIDs 18241,
18242 and 18329.

Microsoft Security Advisory MS11-028:
The Microsoft .Net implementation contains a programming error that may
allow a remote attacker to execute code on an affected system.

A rule to detect attacks targeting this vulnerability is included in
this release and is identified with GID 3, SID 18624.

Microsoft Security Advisory MS11-029:
The Microsoft Graphics Device Interface (GDI) contains a programming
error that may allow a remote attacker to execute code on an affected
system.

A rule to detect attacks targeting this vulnerability is included in
this release and is identified with GID 3, SID 18645.

Microsoft Security Advisory MS11-030:
The Microsoft implementation of the Domain Name System (DNS),
specifically when handling the Link-local Multicast Name Resolution
(LLMNR) protocol, contains a programming error that may allow a remote
attacker to execute code on an affected system.

A rule to detect attacks targeting this vulnerability is included in
this release and is identified with GID 3, SID 18655.

Microsoft Security Advisory MS11-032:
The Microsoft implementation for handling Open-Type fonts contains a
programming error that may allow a remote attacker to execute code on
an affected system.

A rule to detect attacks targeting this vulnerability is included in
this release and is identified with GID 3, SID 18644.

Microsoft Security Advisory MS11-033:
The Microsoft Office Word Converter contains programming errors that
may allow a remote attacker to execute code on an affected system.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 3, SIDs 18642 and 18643.

Microsoft Security Advisory MS11-034:
The Microsoft Windows Operating System contains programming errors that
may allow an attacker to escalate privileges on an affected host.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 3, SIDs 18661 through 18667.

Adobe Security Advisory APSA11-02:
Adobe Flash Player contains a programming error that may allow a remote
attacker to execute code on an affected system.

A previously released rule will detect attacks targeting this
vulnerability and is identified with GID 1, SID 18546.

Support for the upcoming release of Snort 2.9.0.5 is included in this rule pack as well.  When Snort 2.9.0.5 is released, subscribers will have the coverage of the latest detection functionality and ruleset.

In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Tuesday, March 15, 2011

VRT Rule Update for 03/15/2011, MS Tues

Just released, is a rule release for today from the VRT. In this release we introduce 11 new rules and make modifications to 2 more.

In VRT's rule release:
Details:

Adobe Security Advisory APSA11-01:
Adobe Flash Player contains a programming error that may allow a remote
attacker to execute code on an affected system. This problem affects
the Microsoft Windows, Apple Mac OS, Linux and Solaris operating
systems.

The Sourcefire VRT have reports of this vulnerability being exploited
in the wild via an embedded Flash file in a Microsoft Excel document
delivered via email.

Rules to detect attacks targeting this vulnerability are included in
this release and are identified with GID 3, SID 18543, GID 1, SIDs
18545 through 18554.

In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store. Make sure and stay up to date to catch the most emerging threats!

Tuesday, February 8, 2011

VRT Rule update for 2/8/2011

Just updated, is a rule release for today from the VRT.  This rule release contains many updates in several categories, however, the highlights for this release is the following:

Microsoft Security Advisory MS11-003:
Microsoft Internet Explorer suffers from a programming error that may
allow a remote attacker to execute code on a vulnerable system.

Rules to detect attacks targeting this vulnerability are included in
this release and are identified with GID 3, SIDs 18403 and 18404.

Previously released rules to detect attacks targeting this
vulnerability have been updated with the appropriate reference and are
identified with GID 1, SIDs 18196 and 18240.

Microsoft Security Advisory MS11-004:
The Microsoft FTP Service included with IIS, suffers from a programming
error that may allow a remote attacker to execute code on an affected
system.

A previously released rule to detect attacks targeting this
vulnerability has been updated with the appropriate reference and is
identified with GID 1, SID 18243.

Microsoft Security Advisory MS11-005:
Microsoft Windows Server 2003 contains a programming error that may
allow a remote attacker to execute a Denial of Service (DoS) attack
against a vulnerable system.

Rules to detect attacks targeting this vulnerability are included in
this release and are identified with GID 3, SIDs 18406 and 18407.

Microsoft Security Advisory MS11-006:
Microsoft Office suffers from a programming error that may allow a
remote attacker to execute code on a vulnerable system via a malicious
bitmap file.

A rule to detect attacks targeting this vulnerability is included in
this release and is identified with GID 3, SID 18398.

Microsoft Security Advisory MS11-007:
The Microsoft ATMFD Adobe font driver included in Microsoft Windows
contains a programming error that may allow a remote attacker to
execute code on a vulnerable system.

A rule to detect attacks targeting this vulnerability is included in
this release and is identified with GID 3, SID 18402.

Microsoft Security Advisory MS11-008:
Microsoft Visio contains programming errors that may allow a remote
attacker to execute code on a vulnerable system via a malicious Visio
file.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 3, SIDs 18415, 18416 and
18417.

Microsoft Security Advisory MS11-009:
Microsoft Internet Explorer contains a programming error that may allow
a remote attacker to obtain information regarding the vulnerable system
via malicious JScript or VBScript.

A rule to detect attacks targeting this vulnerability is included in
this release and is identified with GID 3, SID 18401.

Microsoft Security Advisory MS11-010:
The Microsoft Windows Client/Server run-time subsystem contains a
programming error that may allow a remote attacker to elevate
privileges on a vulnerable system.

A rule to detect attacks targeting this vulnerability is included in
this release and is identified with GID 3, SID 18400.

Microsoft Security Advisory MS11-011:
The Microsoft Windows kernel contains a programming error that may
allow a remote attacker to elevate privileges on a vulnerable system.

Rules to detect attacks targeting this vulnerability are included in
this release and are identified with GID 3, SIDs 18408 and 18413.

Microsoft Security Advisory MS11-012:
Microsoft Windows systems suffer from programming errors that may allow
remote attackers to elevate privileges on a vulnerable system via
kernel-mode drivers.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 3, SIDs 18409, 18410, 18411
and 18412.

Microsoft Security Advisory MS11-013:
The Microsoft Windows Kerberos implementation may allow a remote
attacker to downgrade the authentication mechanism to use DES so that
the vulnerable system is subject to a spoofing vulnerability.

A rule to detect attacks targeting this vulnerability is included in
this release and is identified with GID 3, SID 18414.

Microsoft Security Advisory MS11-014:
The Microsoft Local Security Authority Subsystem Service (LSASS)
contains a programming error that may allow a remote attacker to
execute code with elevated privileges on a vulnerable system.

A rule to detect attacks targeting this vulnerability is included in
this release and is identified with GID 3, SID 18405.

Adobe Security Advisory APSB11-03:
Adobe Reader and Acrobat contain programming errors that may allow a
remote attacker to execute code on a vulnerable system.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with GID 3, SIDs 18418 through 18421,
18444 and 18447 through 18456.


In order to subscribe now to the VRT's newest rule detection functionality, you can subscribe for as low as $29 US dollars a year for personal users, be sure and see our business pricing as well at http://www.snort.org/store.  Make sure and stay up to date to catch the most emerging threats!