Rule Update

17-012 (March 14, 2017)


  DESCRIPTION

* indicates a new version of an existing rule

Deep Packet Inspection Rules:

DCERPC Services
1008224 - Microsoft Windows SMB Remote Code Execution Vulnerabilities (CVE-2017-0144 and CVE-2017-0146)
1008225 - Microsoft Windows SMB Remote Code Execution Vulnerability (CVE-2017-0145)
1008228 - Microsoft Windows SMB Remote Code Execution Vulnerability (CVE-2017-0148)


DCERPC Services - Client
1008187 - Microsoft Office OLE DLL Loading Vulnerability Over Network Share (CVE-2016-7275)
1008177 - Microsoft Windows DLL Loading Vulnerability Over Network Share (CVE-2017-0039)


Microsoft Office
1008165 - Microsoft Office Information Disclosure Vulnerability (CVE-2017-0027)
1008245 - Microsoft Office Information Disclosure Vulnerability (CVE-2017-0105)
1008242 - Microsoft Office Memory Corruption Vulnerability (CVE-2017-0006)
1008163 - Microsoft Office Memory Corruption Vulnerability (CVE-2017-0019)
1008164 - Microsoft Office Memory Corruption Vulnerability (CVE-2017-0020)
1008167 - Microsoft Office Memory Corruption Vulnerability (CVE-2017-0030 and CVE-2016-0031)
1008243 - Microsoft Office Memory Corruption Vulnerability (CVE-2017-0052)
1008244 - Microsoft Office Memory Corruption Vulnerability (CVE-2017-0053)


Web Client Common
1008121* - Adobe Acrobat And Reader Multiple Security Vulnerabilities (APSB17-01) - 2
1008237 - Microsoft Windows COM Elevation Of Privilege Vulnerability (CVE-2017-0100)
1008170 - Microsoft Windows DLL Loading Vulnerability Over WebDAV (CVE-2017-0039)
1008176 - Microsoft Windows GDI Elevation Of Privilege Vulnerability (CVE-2017-0047)
1008238 - Microsoft Windows GDI+ Information Disclosure vulnerability (CVE-2017-0060)
1008239 - Microsoft Windows GDI+ Information Disclosure vulnerability (CVE-2017-0062)
1008240 - Microsoft Windows GDI+ Information Disclosure vulnerability (CVE-2017-0073)
1008241 - Microsoft Windows GDI+ Remote Code Execution Vulnerability (CVE-2017-0108)
1008169 - Microsoft Windows Graphics Component Remote Code Execution Vulnerability (CVE-2017-0014)
1008172 - Microsoft Windows Kernel Elevation Of Privilege Vulnerability (CVE-2017-0050)
1008248 - Microsoft Windows Multiple Elevation Of Privilege Vulnerabilities (MS17-018)
1008168 - Microsoft Windows PDF Library Memory Corruption Vulnerability (CVE-2017-0023)
1008247 - Microsoft Windows Registry Elevation Of Privilege Vulnerability (CVE-2017-0103)
1008236 - Microsoft Windows Uniscribe Multiple Remote Code Execution Vulnerabilities (MS17-011)
1008234 - Microsoft Windows Uniscribe Multiple Remote Code Execution Vulnerabilities (MS17-011) - 1
1008235 - Microsoft Windows Uniscribe Multiple Remote Code Execution Vulnerabilities (MS17-011) - 2
1008195 - Sun JDK JPG/BMP Parser Multiple Vulnerabilities (CVE-2007-2788)


Web Client Internet Explorer/Edge
1008157 - Microsoft Edge Information Disclosure Vulnerability (CVE-2017-0011)
1008159 - Microsoft Edge Information Disclosure Vulnerability (CVE-2017-0017)
1008211 - Microsoft Edge Information Disclosure Vulnerability (CVE-2017-0065)
1008210 - Microsoft Edge Memory Corruption Vulnerability (CVE-2017-0034)
1008219 - Microsoft Edge Out Of Bounds Read Vulnerability (CVE-2017-0131)
1008156 - Microsoft Edge Scripting Engine Memory Corruption Vulnerability (CVE-2017-0010)
1008158 - Microsoft Edge Scripting Engine Memory Corruption Vulnerability (CVE-2017-0015)
1008160 - Microsoft Edge Scripting Engine Memory Corruption Vulnerability (CVE-2017-0032)
1008161 - Microsoft Edge Scripting Engine Memory Corruption Vulnerability (CVE-2017-0035)
1008213 - Microsoft Edge Scripting Engine Memory Corruption Vulnerability (CVE-2017-0067)
1008216 - Microsoft Edge Scripting Engine Memory Corruption Vulnerability (CVE-2017-0070)
1008217 - Microsoft Edge Scripting Engine Memory Corruption Vulnerability (CVE-2017-0071)
1008218 - Microsoft Edge Scripting Engine Memory Corruption Vulnerability (CVE-2017-0094)
1008221 - Microsoft Edge Scripting Engine Memory Corruption Vulnerability (CVE-2017-0140)
1008222 - Microsoft Edge Scripting Engine Memory Corruption Vulnerability (CVE-2017-0141)
1008220 - Microsoft Edge Scripting Engine Memory Corruption Vulnerabilty (CVE-2017-0133)
1008212 - Microsoft Edge Security Feature Bypass Vulnerability (CVE-2017-0066)
1008215 - Microsoft Edge Spoofing Vulnerability (CVE-2017-0069)
1008150 - Microsoft Internet Explorer And Edge Memory Corruption Vulnerability (CVE-2017-0009)
1008152 - Microsoft Internet Explorer And Edge Spoofing Vulnerability (CVE-2017-0033)
1008249 - Microsoft Internet Explorer Elevation Of Privilege Vulnerability (CVE-2017-0154)
1008149 - Microsoft Internet Explorer Information Disclosure Vulnerability (CVE-2017-0008)
1008208 - Microsoft Internet Explorer Information Disclosure Vulnerability (CVE-2017-0059)
1008151 - Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2017-0018)
1008154 - Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2017-0040)
1008209 - Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2017-0130)
1008250 - Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2017-0149)
1008155 - Microsoft Internet Explorer Scripting Engine Information Disclosure Vulnerability (CVE-2017-0049)
1008174 - Microsoft Windows DirectShow Information Disclosure Vulnerability (CVE-2017-0042)
1008173 - Microsoft XML Core Service Information Disclosure Vulnerability (CVE-2017-0022)


Web Server Common
1005839* - Identified XML External Entity Injection In HTTP Request


Web Server Miscellaneous
1008129* - IBM WebSphere Application Server Remote Code Execution Vulnerability (CVE-2016-5983)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.