Rule Update

21-002 (January 12, 2021)


  DESCRIPTION

* indicates a new version of an existing rule

Deep Packet Inspection Rules:

Directory Server LDAP
1010724 - Microsoft Windows Active Directory IntegratedDNS Remote Code Execution Vulnerability (CVE-2020-0718)


HP LoadRunner Agent Protocol
1010690* - HP LoadRunner 'launcher.dll' Stack Buffer Overflow Vulnerability (CVE-2015-2110)


IBM WebSphere Application Server
1010343* - IBM WebSphere UploadFileArgument Deserialization Vulnerability (CVE-2020-4448)


Microsoft Office
1010719 - Microsoft Excel Remote Code Execution Vulnerability (CVE-2021-1713)
1010720 - Microsoft Word Remote Code Execution Vulnerability (CVE-2021-1715)


Suspicious Client Ransomware Activity
1010714 - Identified HTTP Trojan-Downloader.Win32.Cometer.bfc C&C Traffic Request


Trend Micro OfficeScan
1010709 - Trend Micro Apex One Multiple Information Disclosure Vulnerabilities (CVE-2020-28573 and CVE-2020-28576)
1010708 - Trend Micro OfficeScan Multiple Information Disclosure Vulnerabilities (CVE-2020-28582 and CVE-2020-28583)


Web Application Common
1010661* - BlackCat CMS Cross-Site Request Forgery Bypass Vulnerability (CVE-2020-25453)
1010663* - Bludit CMS Brute Force Bypass Vulnerability (CVE-2019-17240)
1010668* - FUEL CMS Remote Code Execution Vulnerability (CVE-2018-16763)
1010654* - Opmantek Open-AuditIT Professional Cross Site Request Forgery Vulnerability (CVE-2018-8979)


Web Application PHP Based
1010705* - WordPress 'Canto' Plugin Multiple Server-Side Request Forgery Vulnerabilities


Web Client Common
1010711 - Google Chrome Buffer Overflow Vulnerability (CVE-2019-5782)
1010706 - Microsoft 3D Builder GLB File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability (ZDI-CAN-11486)
1010700 - Microsoft Windows Defender Remote Code Execution Vulnerability (CVE-2021-1647)


Web Server Common
1010692* - CentOS Web Panel Arbitrary File Write Remote Code Execution Vulnerability (CVE-2020-15623)
1010687* - Oracle ADF Faces Deserialization of Untrusted Data Vulnerability (CVE-2019-2904)
1010697* - Trend Micro InterScan Messaging Security Virtual Appliance Widget Information Disclosure Vulnerability (CVE-2020-27019)


Web Server HTTPS
1010723 - Identified Generic PHP Webshell Payload Over HTTP


Web Server Miscellaneous
1010717 - SolarWinds Orion Platform Authentication Bypass Vulnerability (CVE-2020-10148)
1010691* - SolarWinds Orion Remote Code Execution Vulnerability (CVE-2020-14005)


Web Server Nagios
1010598* - Nagios XI 'admin_views.inc.php' Arbitrary File Overwrite Vulnerability
1010696 - Nagios XI SNMP Trap SQL Injection Vulnerability


Web Server SharePoint
1010702 - Microsoft SharePoint Authenticated Remote Code Execution Vulnerability (CVE-2021-1707)
1010707 - Microsoft SharePoint Remote Code Execution Vulnerability (CVE-2020-0971)


Webmin
1010704 - Webmin Arbitrary Remote Command Execution Vulnerability (CVE-2020-35606)


Windows SMB Client
1010701 - Microsoft Windows Defender Remote Code Execution Vulnerability Over SMB (CVE-2021-1647)


Zoho ManageEngine
1010698* - Zoho ManageEngine Applications Manager 'showMonitorGroupView' SQL Injection Vulnerability


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.