Rule Update

16-014 (May 10, 2016)


  DESCRIPTION

* indicates a new version of an existing rule

Deep Packet Inspection Rules:

Application Control For File Sharing
1007608 - Application Control For Amazon Cloud Drive
1007605 - Application Control For BOX


Microsoft Office
1007619 - Microsoft Office Graphics RCE Vulnerability (CVE-2016-0183)
1007617 - Microsoft Office Memory Corruption Vulnerability (CVE-2016-0126)
1007618 - Microsoft Office Memory Corruption Vulnerability (CVE-2016-0140)


Suspicious Client Application Activity
1007578 - Ransomware CryptFile
1007576* - Ransomware Cryptesla
1007579 - Ransomware HTTP Request
1007577* - Ransomware Hydra
1007581* - Ransomware Lectool
1007602 - Ransomware Locky
1007601 - Ransomware TCP Request


Suspicious Server Application Activity
1007580 - Ransomware HTTP Request-1
1007582* - Ransomware Lectool-1
1007533 - Ransomware TCP Request-1


Web Application Common
1007609* - ImageMagick Remote Code Execution Vulnerability (CVE-2016-3714)


Web Application PHP Based
1007597* - Joomla Akeeba Kickstart Unserialize Remote Code Execution Vulnerability (CVE-2014-7228)
1006786* - PHP exif_process_unicode() Function Uninitialized Pointer Freeing Remote Code Execution Vulnerability
1007178* - WordPress Font Plugin Path Traversal Vulnerability (CVE-2015-7683)


Web Application Ruby Based
1007520* - RubyGems Actionpack Denial Of Service Vulnerability (CVE-2013-6414)


Web Client Common
1007629 - Adobe Acrobat And Reader Integer Overflow Vulnerability (CVE-2016-1043)
1007630 - Adobe Acrobat And Reader Memory Corruption Vulnerability (CVE-2016-1063)
1007633 - Adobe Acrobat And Reader Memory Corruption Vulnerability (CVE-2016-1073)
1007631 - Adobe Acrobat And Reader Use After Free Vulnerability (CVE-2016-1065)
1007632 - Adobe Acrobat And Reader Use After Free Vulnerability (CVE-2016-1070)
1007078* - Adobe Flash Player Memory Corruption Vulnerability (CVE-2015-5574)
1007453* - Adobe Flash Player Use After Free Vulnerability (CVE-2016-0984)
1007568* - Adobe Flash Player Use After Free Vulnerability (CVE-2016-1016)
1007594* - Apple QuickTime 'moov' Atom Heap Corruption Remote Code Execution Vulnerability
1007595* - Apple QuickTime Atom Processing Heap Corruption Remote Code Execution Vulnerability
1007611 - ImageMagick Remote Code Execution Vulnerability (CVE-2016-3714) - 1
1007620 - Microsoft Windows Graphics Component Information Disclosure Vulnerability (CVE-2016-0168)
1007621 - Microsoft Windows Graphics Component Information Disclosure Vulnerability (CVE-2016-0169)
1007622 - Microsoft Windows Graphics Component RCE Vulnerability (CVE-2016-0170)
1007624 - Microsoft Windows Media Center Remote Code Execution Vulnerability (CVE-2016-0185)
1007537 - Microsoft Windows OpenType Font Parsing Vulnerability (CVE-2016-0120)


Web Client Internet Explorer/Edge
1007615 - Microsoft Edge Memory Corruption Vulnerability (CVE-2016-0191)
1007616 - Microsoft Edge Scripting Engine Memory Corruption Vulnerability (CVE-2016-0193)
1007614 - Microsoft Internet Explorer And Edge Memory Corruption Vulnerability (CVE-2016-0192)
1007177* - Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2015-6086)
1007407* - Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2016-0063)
1007471* - Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2016-0106)
1007612 - Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability (CVE-2016-0187)
1007613 - Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability (CVE-2016-0189)
1007623 - Microsoft Windows Direct3D Use After Free Vulnerability (CVE-2016-0184)


Web Server Common
1007213 - Disallow Upload Of A Class File
1007212 - Disallow Upload Of An Archive File


Web Server Miscellaneous
1007532* - JBoss Application Server Unauthenticated Remote Command Execution Vulnerability
1007607 - RedHat JBoss Operations Network ContentManager Remote Code Execution Vulnerability (CVE-2015-0297)
1007606 - RedHat JBoss WildFly Application Server Information Disclosure Vulnerability (CVE-2016-0793)


Windows Services RPC Server
1007596* - Identified Suspicious File Extension Rename Activity Over Network Share


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.