Rule Update

24-021 (April 23, 2024)


  DESCRIPTION

* indicates a new version of an existing rule

Deep Packet Inspection Rules:

Arcserve Unified Data Protection
1012019 - Arcserve Unified Data Protection Denial of Service Vulnerability (CVE-2024-0801)
1011972* - Arcserve Unified Data Protection Directory Traversal Vulnerability (CVE-2023-42000)
1011970* - Arcserve Unified Data Protection Remote Code Execution Vulnerability (CVE-2023-41998)


DCERPC Services
1004600* - Microsoft Active Directory 'BROWSER ELECTION' Buffer Overflow Vulnerability
1005140* - Print Spooler Service Format String Vulnerability (CVE-2012-1851)
1004401* - Print Spooler Service Impersonation Vulnerability
1004346* - SMB Pool Overflow Vulnerability
1004355* - SMB Stack Exhaustion Vulnerability
1004641* - SMB Transaction Parsing Vulnerability (CVE-2011-0661)
1004348* - SMB Variable Validation Vulnerability


DCERPC Services - Client
1004821* - Active Accessibility Insecure Library Loading Vulnerability (CVE-2011-1247)
1004700* - DFS Memory Corruption Vulnerability (CVE-2011-1868)
1004762* - Data Access Components Insecure Library Loading Vulnerability Over Network Share (CVE-2011-1975)
1004563* - Microsoft Windows 'CreateSizedDIBSECTION()' Thumbnail View Stack Buffer Overflow Vulnerability Over Network Share
1004697* - OLE Automation Underflow Vulnerability ( CVE-2011-0658 )
1004897* - Object Packager Insecure Executable Launching Vulnerability Over Network Share (CVE-2012-0009)
1004877* - PowerPoint Insecure Library Loading Vulnerability Over Network Share (CVE-2011-3396)
1005139* - Remote Administration Protocol Denial Of Service Vulnerability (CVE-2012-1850)
1004100* - SMB Client Message Size Vulnerability
1004637* - SMB Client Response Parsing Vulnerability (CVE-2011-0660)
1004692* - SMB Response Parsing Vulnerability (CVE-2011-1268)
1004775* - Telnet Handler Remote Code Execution Vulnerability Over Network Share (CVE-2011-1961)
1005081* - Vulnerability In Windows Shell Could Allow Remote Code Execution (CVE-2012-0175)
1004797* - Windows Components Insecure Library Loading Vulnerability Over Network Share (CVE-2011-1991)
1004843* - Windows Mail Insecure Library Loading Vulnerability Over Network Share (CVE-2011-2016)


Elastic Kibana And Elasticsearch
1011909* - Elastic Kibana Upgrade Assistant Telemetry Collector Prototype Pollution Vulnerability


HP Intelligent Management Center (IMC)
1011941* - Apache OFBiz Insecure Deserialization Vulnerability (CVE-2023-49070)


JetBrains TeamCity
1012020 - JetBrains TeamCity Cross-Site Scripting Vulnerability (CVE-2024-31138)


Link-Local Multicast Name Resolution
1004645* - DNS Query Vulnerability (CVE-2011-0657)


Nextgen Mirth Connect
1012008 - Nextgen Mirth Connect Insecure Deserialization Vulnerability (CVE-2023-43208)


Remote Desktop Protocol Server
1004949* - Remote Desktop Protocol Vulnerability (CVE-2012-0002)
1005138* - Remote Desktop Protocol Vulnerability (CVE-2012-2526)


Web Server Miscellaneous
1012026 - CrushFTP Remote Code Execution Vulnerability (CVE-2023-43177)
1012017 - Identified Restricted file upload with specific extension


Web Server Squid
1011939* - Squid Proxy Heap Buffer Overflow Vulnerability (CVE-2023-46847)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.