Deep Security Center

* indicates a new version of an existing rule

Deep Packet Inspection Rules:

DCERPC Services
1008224 - Microsoft Windows SMB Remote Code Execution Vulnerabilities (CVE-2017-0144 and CVE-2017-0146)
1008225 - Microsoft Windows SMB Remote Code Execution Vulnerability (CVE-2017-0145)
1008228 - Microsoft Windows SMB Remote Code Execution Vulnerability (CVE-2017-0148)


DCERPC Services - Client
1008187 - Microsoft Office OLE DLL Loading Vulnerability Over Network Share (CVE-2016-7275)
1008177 - Microsoft Windows DLL Loading Vulnerability Over Network Share (CVE-2017-0039)


Microsoft Office
1008165 - Microsoft Office Information Disclosure Vulnerability (CVE-2017-0027)
1008245 - Microsoft Office Information Disclosure Vulnerability (CVE-2017-0105)
1008242 - Microsoft Office Memory Corruption Vulnerability (CVE-2017-0006)
1008163 - Microsoft Office Memory Corruption Vulnerability (CVE-2017-0019)
1008164 - Microsoft Office Memory Corruption Vulnerability (CVE-2017-0020)
1008167 - Microsoft Office Memory Corruption Vulnerability (CVE-2017-0030 and CVE-2016-0031)
1008243 - Microsoft Office Memory Corruption Vulnerability (CVE-2017-0052)
1008244 - Microsoft Office Memory Corruption Vulnerability (CVE-2017-0053)


Web Client Common
1008121* - Adobe Acrobat And Reader Multiple Security Vulnerabilities (APSB17-01) - 2
1008237 - Microsoft Windows COM Elevation Of Privilege Vulnerability (CVE-2017-0100)
1008170 - Microsoft Windows DLL Loading Vulnerability Over WebDAV (CVE-2017-0039)
1008176 - Microsoft Windows GDI Elevation Of Privilege Vulnerability (CVE-2017-0047)
1008238 - Microsoft Windows GDI+ Information Disclosure vulnerability (CVE-2017-0060)
1008239 - Microsoft Windows GDI+ Information Disclosure vulnerability (CVE-2017-0062)
1008240 - Microsoft Windows GDI+ Information Disclosure vulnerability (CVE-2017-0073)
1008241 - Microsoft Windows GDI+ Remote Code Execution Vulnerability (CVE-2017-0108)
1008169 - Microsoft Windows Graphics Component Remote Code Execution Vulnerability (CVE-2017-0014)
1008172 - Microsoft Windows Kernel Elevation Of Privilege Vulnerability (CVE-2017-0050)
1008248 - Microsoft Windows Multiple Elevation Of Privilege Vulnerabilities (MS17-018)
1008168 - Microsoft Windows PDF Library Memory Corruption Vulnerability (CVE-2017-0023)
1008247 - Microsoft Windows Registry Elevation Of Privilege Vulnerability (CVE-2017-0103)
1008236 - Microsoft Windows Uniscribe Multiple Remote Code Execution Vulnerabilities (MS17-011)
1008234 - Microsoft Windows Uniscribe Multiple Remote Code Execution Vulnerabilities (MS17-011) - 1
1008235 - Microsoft Windows Uniscribe Multiple Remote Code Execution Vulnerabilities (MS17-011) - 2
1008195 - Sun JDK JPG/BMP Parser Multiple Vulnerabilities (CVE-2007-2788)


Web Client Internet Explorer/Edge
1008157 - Microsoft Edge Information Disclosure Vulnerability (CVE-2017-0011)
1008159 - Microsoft Edge Information Disclosure Vulnerability (CVE-2017-0017)
1008211 - Microsoft Edge Information Disclosure Vulnerability (CVE-2017-0065)
1008210 - Microsoft Edge Memory Corruption Vulnerability (CVE-2017-0034)
1008219 - Microsoft Edge Out Of Bounds Read Vulnerability (CVE-2017-0131)
1008156 - Microsoft Edge Scripting Engine Memory Corruption Vulnerability (CVE-2017-0010)
1008158 - Microsoft Edge Scripting Engine Memory Corruption Vulnerability (CVE-2017-0015)
1008160 - Microsoft Edge Scripting Engine Memory Corruption Vulnerability (CVE-2017-0032)
1008161 - Microsoft Edge Scripting Engine Memory Corruption Vulnerability (CVE-2017-0035)
1008213 - Microsoft Edge Scripting Engine Memory Corruption Vulnerability (CVE-2017-0067)
1008216 - Microsoft Edge Scripting Engine Memory Corruption Vulnerability (CVE-2017-0070)
1008217 - Microsoft Edge Scripting Engine Memory Corruption Vulnerability (CVE-2017-0071)
1008218 - Microsoft Edge Scripting Engine Memory Corruption Vulnerability (CVE-2017-0094)
1008221 - Microsoft Edge Scripting Engine Memory Corruption Vulnerability (CVE-2017-0140)
1008222 - Microsoft Edge Scripting Engine Memory Corruption Vulnerability (CVE-2017-0141)
1008220 - Microsoft Edge Scripting Engine Memory Corruption Vulnerabilty (CVE-2017-0133)
1008212 - Microsoft Edge Security Feature Bypass Vulnerability (CVE-2017-0066)
1008215 - Microsoft Edge Spoofing Vulnerability (CVE-2017-0069)
1008150 - Microsoft Internet Explorer And Edge Memory Corruption Vulnerability (CVE-2017-0009)
1008152 - Microsoft Internet Explorer And Edge Spoofing Vulnerability (CVE-2017-0033)
1008249 - Microsoft Internet Explorer Elevation Of Privilege Vulnerability (CVE-2017-0154)
1008149 - Microsoft Internet Explorer Information Disclosure Vulnerability (CVE-2017-0008)
1008208 - Microsoft Internet Explorer Information Disclosure Vulnerability (CVE-2017-0059)
1008151 - Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2017-0018)
1008154 - Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2017-0040)
1008209 - Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2017-0130)
1008250 - Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2017-0149)
1008155 - Microsoft Internet Explorer Scripting Engine Information Disclosure Vulnerability (CVE-2017-0049)
1008174 - Microsoft Windows DirectShow Information Disclosure Vulnerability (CVE-2017-0042)
1008173 - Microsoft XML Core Service Information Disclosure Vulnerability (CVE-2017-0022)


Web Server Common
1005839* - Identified XML External Entity Injection In HTTP Request


Web Server Miscellaneous
1008129* - IBM WebSphere Application Server Remote Code Execution Vulnerability (CVE-2016-5983)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

Web Server Miscellaneous
1008207* - Apache Struts2 Remote Code Execution Vulnerability (CVE-2017-5638)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

DNS Client
1008203 - DNSMessenger Malware C&C Traffic Over DNS Protocol
1008204 - DNSMessenger Malware Domain Blocker


Microsoft Office
1004312* - Identified Suspicious Microsoft Word Document


NTP Server Linux
1007741 - NTP Crypto-NAK Packets Symmetric Association Authentication Bypass Vulnerability (CVE-2015-7871)


P2P Applications
1007034* - Share EX2 P2P
1003086* - Winny


Web Application PHP Based
1006386* - PHP 'unserialize()' Integer Overflow Vulnerability (CVE-2014-3669)
1008135 - PHP Exif Null Pointer Dereference Vulnerability (CVE-2016-6292)
1007289 - PHP cURL Lib NULL Byte Injection Vulnerability
1008182 - PHP phar_parse_pharfile Integer Overflow Vulnerability (CVE-2016-10159)
1007222* - WordPress Ajax Load More Plugin File Upload Vulnerability
1008186 - phpMyAdmin Authenticated Remote Code Execution Vulnerability (CVE-2013-3238)


Web Client Common
1004870* - Identified Suspicious Jar File


Web Client Internet Explorer/Edge
1008064* - Microsoft Edge Memory Corruption Vulnerability (CVE-2016-7288)


Web Server Miscellaneous
1008104 - Apache ActiveMQ Multiple Remote Code Execution Vulnerabilities (CVE-2016-3088)
1008207 - Apache Struts2 Remote Code Execution Vulnerability (CVE-2017-5638)
1008129* - IBM WebSphere Application Server Remote Code Execution Vulnerability (CVE-2016-5983)


Web Server Oracle
1004840* - Oracle Application Server Web Cache HTTP Request Method Heap Overrun Vulnerability


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

Backup Server IBM Tivoli Storage Manager FastBack Server
1007356* - IBM Tivoli Storage Manager FastBack Server Buffer Overflow Vulnerability (CVE-2015-1924)


Database Oracle
1003340* - Oracle Database Trigger MDSYS.SDO_TOPO_DROP_FTBL SQL Injection


Microsoft Office
1004311* - Identified Suspicious Microsoft PowerPoint Document


VoIP Smart
1008087* - IBM WebSphere Application Server SIP Processing DoS Vulnerability (CVE-2016-2960)


Web Application Common
1000608* - Generic SQL Injection Prevention


Web Application PHP Based
1008144 - PHP Remote Code Execution Vulnerability (CVE-2017-5340)


Web Client Common
1004335* - Apple QuickTime 'QuickTimeStreaming.qtx' Remote Stack Buffer Overflow
1008185 - Identified Suspicious Obfuscated PDF Document
1008028 - Microsoft Windows File Manager Remote Code Execution Vulnerability (CVE-2016-7212)
1008147 - Microsoft Windows RPC Network Data Representation Engine Remote Code Execution Vulnerability (CVE-2016-0178)


Web Client Mozilla Firefox
1007061* - Mozilla Firefox Arbitrary JavaScript Code Execution
1007062* - Mozilla Firefox Arbitrary JavaScript Execution Vulnerability (CVE-2015-0802)
1008052* - Mozilla Firefox SVG Animation Use After Free Vulnerability (CVE-2016-9079)


Web Server Adobe ColdFusion
1008113 - Adobe ColdFusion OOXML XXE Information Disclosure Vulnerability (CVE-2016-4264)


Web Server Common
1005671* - PHP SSL Module "subjectAltNames" NULL Byte Handling Security Vulnerability


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

Web Client Internet Explorer/Edge
1008153 - Microsoft Internet Explorer And Edge Memory Corruption Vulnerability (CVE-2017-0037)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

DCERPC Services - Client
1008138* - Microsoft Windows SMB Tree Connect Response Denial Of Service Vulnerability (CVE-2017-0016)


DNS Client
1008180 - ISC BIND Inconsistent DS Record Assertion Failure Denial Of Service Vulnerability (CVE-2016-9444)
1008136 - ISC BIND RRSIG Record Response Assertion Failure Denial Of Service (CVE-2016-9147)


Suspicious Client Ransomware Activity
1007579* - Ransomware HTTP Request


Unix Kerberos
1008095* - MIT Kerberos 'kadmin' DB Denial Of Service Vulnerability (CVE-2016-3119)


Web Application Common
1007609* - ImageMagick Remote Code Execution Vulnerability (CVE-2016-3714)


Web Application PHP Based
1008125 - Joomla Denial Of Service Vulnerability (CVE-2013-3242)
1008037 - PHP GC Use After Free Vulnerability (CVE-2016-5771)
1008131 - PHP Unserialize() ZVAL Reference Counter Overflow Vulnerability (CVE-2007-1286)
1008140* - WordPress REST API Unauthenticated Content Injection Vulnerability
1008132* - phpMyAdmin RegEx Pattern Modifier Code Injection Vulnerability (CVE-2016-5734)


Web Client Common
1008121* - Adobe Acrobat And Reader Multiple Security Vulnerabilities (APSB17-01) - 2
1008183 - Adobe Flash Player Multiple Security Vulnerabilities (APSB17-04)
1008171 - Microsoft Windows Graphics Component Information Disclosure Vulnerability (CVE-2017-0038)
1008108 - Oracle Java Uninitialized Object Generation Remote Code Execution Vulnerability (CVE-2016-3606)


Web Client Internet Explorer/Edge
1008064* - Microsoft Edge Memory Corruption Vulnerability (CVE-2016-7288)


Web Media Applications
1002451* - YouTube


Web Server Miscellaneous
1008097* - Identified Apache Struts Incorrect Default 'excludeParams' Security Bypass Vulnerability
1008141 - Jetty Path Sanitization Vulnerability (CVE-2016-4800)
1008093* - Oracle GlassFish Server Username And Password Brute Force Vulnerability (CVE-2011-0807)


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

Backup Server IBM Tivoli Storage Manager FastBack Server
1007357* - IBM Tivoli Storage Manager FastBack Server Buffer Overflow (CVE-2015-1929)


DCERPC Services
1008123* - Microsoft Windows Local Security Authority Subsystem Service Denial Of Service Vulnerability (CVE-2016-7237)


DCERPC Services - Client
1008138* - Microsoft Windows SMB Tree Connect Response Denial Of Service Vulnerability (CVE-2017-0016)


DNS Client
1008128* - ISC BIND ANY Query Assertion Failure Vulnerability (CVE-2016-9131)
1008115* - ISC BIND DNAME Resource Records Denial Of Service Vulnerability (CVE-2016-1286)


Directory Server LDAP
1007360* - IBM Domino LDAP Server Remote Execution Vulnerability (CVE-2015-0117)
1008051* - Samba Active Directory Server Denial Of Service Vulnerability (CVE-2015-3223)


HP OpenView
1008110* - HP Data Protector Buffer Overflow Vulnerability (CVE-2016-2005)
1008114* - HP Data Protector Multiple Remote Code Execution Vulnerabilities
1008109* - HP Data Protector Remote Code Execution Vulnerability (CVE-2016-2007)


HP OpenView Network Node Manager
1007466* - HP OpenView Network Node Manager Ovalarmsrv Service Buffer Overflow (CVE-2008-1852)


Microsoft Office
1008075* - Microsoft Office Information Disclosure Vulnerability (CVE-2016-7264)
1008078* - Microsoft Office Memory Corruption Vulnerability (CVE-2016-7289)


NTP Server Linux
1007383* - NTP Configuration Directive File Overwrite Vulnerability (CVE-2015-7703)
1007399* - NTP Long Control Packet Message Denial Of Service Vulnerability (CVE-2015-7855)
1008091* - NTP Oversized UDP Packet Denial Of Service Vulnerability (CVE-2016-9312)


Suspicious Client Application Activity
1005067* - Identified Potentially Harmful Client Traffic
1005283* - Identified Potentially Malicious RAT Traffic - I
1005299* - Identified Potentially Malicious RAT Traffic - III
1005300* - Identified Potentially Malicious RAT Traffic - IV
1005473* - Identified Potentially Malicious RAT Traffic - V
1006247* - Identified Potentially Malicious RAT Traffic - VI
1007116* - VMware vCenter Java JMX Server Insecure Configuration Java Code Execution Vulnerability


Suspicious Server Application Activity
1005974* - Identified DNS Reflected Denial Of Service
1006560* - Identified Microsoft SQL Server Resolution Service Distributed Denial Of Service Attack
1006240* - Identified NTP Reflected Denial Of Service
1005090* - Identified Potentially Harmful Server Traffic
1005957* - Identified SNMP Reflected Denial Of Service
1005910* - Identified ntpd 'monlist' Query Reflected Denial Of Service Attack
1005517* - Restrict Maximum Packet (Transport Data Length) Size


Unix Kerberos
1008095 - MIT Kerberos 'kadmin' DB Denial Of Service Vulnerability (CVE-2016-3119)


Web Application PHP Based
1007178* - WordPress Font Plugin Path Traversal Vulnerability (CVE-2015-7683)
1008132 - phpMyAdmin RegEx Pattern Modifier Code Injection Vulnerability (CVE-2016-5734)


Web Client Common
1008124* - Adobe Acrobat And Reader Multiple Security Vulnerabilities (APSB17-01) - 1
1008121* - Adobe Acrobat And Reader Multiple Security Vulnerabilities (APSB17-01) - 2
1008133* - Cisco WebEx Plugin Magic URL Arbitrary Remote Command Execution Vulnerability
1004114* - Identified Malicious Adobe SWF File
1008139 - Linux Kernel Use After Free Remote Code Execution Vulnerability (CVE-2016-7117)
1008068* - Microsoft Windows Graphics Remote Code Execution Vulnerability (CVE-2016-7272)
1008052* - Mozilla Firefox SVG Animation Use After Free Vulnerability (CVE-2016-9079)


Web Proxy Squid
1008103* - Squid Proxy ESI Response Handler Buffer Overflow Vulnerability (CVE-2016-4054)
1008101 - Squid Proxy ESI Response Processing Denial Of Service Vulnerability (CVE-2016-4555)


Web Server Common
1000473* - Parameter Name Length Restriction


Web Server Miscellaneous
1008120* - Apache Jetspeed Portal Site Manager ZIP File Upload Directory Traversal (CVE-2016-0709)
1008129 - IBM WebSphere Application Server Remote Code Execution Vulnerability (CVE-2016-5983)
1008097 - Identified Apache Struts Incorrect Default 'excludeParams' Security Bypass Vulnerability
1008093 - Oracle GlassFish Server Username And Password Brute Force Vulnerability (CVE-2011-0807)


Web Server Oracle HTTPS
1003212* - Oracle Secure Backup exec_qr() Command Injection Vulnerability


Windows Services RPC Client DCERPC
1007538* - Windows Client Port Mapper Decoder


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

DCERPC Services - Client
1008138 - Microsoft Windows SMB Tree Connect Response Denial Of Service Vulnerability (CVE-2017-0016)


Web Application PHP Based
1008140 - WordPress REST API Unauthenticated Content Injection Vulnerability


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

Web Client Common
1008133 - Cisco WebEx Plugin Magic URL Arbitrary Remote Command Execution Vulnerability


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

There are no new or updated Log Inspection Rules in this Security Update.
* indicates a new version of an existing rule

Deep Packet Inspection Rules:

BIND RNDC
1008099 - ISC BIND rndc Control Channel Denial Of Service Vulnerability (CVE-2016-1285)


DCERPC Services
1007596* - Identified Possible Ransomware File Extension Rename Activity Over Network Share
1008119 - Microsoft Windows Local Security Authority Subsystem Service (LSASS) Denial Of Service Vulnerability (CVE-2017-0004)


DCERPC Services - Client
1007913* - Identified Possible Ransomware File Extension Rename Activity Over Network Share - Client


DNS Client
1008053* - ISC BIND DNAME Answer Handling Denial Of Service Vulnerability (CVE-2016-8864)
1007740* - ISC BIND Multiple DNS Cookies Denial Of Service Vulnerability (CVE-2016-2088)
1008085 - Nginx DNS UDP Packet Handler Crash Denial Of Service Vulnerability (CVE-2016-0742)


DNS Server
1008092 - ISC BIND Assertion Failure Denial Of Service Vulnerability (CVE-2016-2848)
1008105 - PowerDNS Authoritative Server Long Qname Denial Of Service Vulnerability (CVE-2016-5426)


Directory Server LDAP
1007360 - IBM Domino LDAP Server Remote Execution Vulnerability (CVE-2015-0117)
1007932* - Microsoft Windows Remote Code Execution Vulnerability (CVE-2016-3368)


ISC LightWeight DNS Resolver
1008100 - ISC BIND Long Name Query DOS Vulnerability (CVE-2016-2775)


Microsoft Office
1008116 - Microsoft Office Memory Corruption Vulnerability (CVE-2017-0003)


NTP Server Linux
1008040* - NTP AutoKey Malicious Message Multiple Denial Of Service Vulnerabilities
1007383* - NTP Configuration Directive File Overwrite Vulnerability (CVE-2015-7703)
1008086 - NTP Daemon CRYPTO_NAK Denial Of Service Vulnerability (CVE-2016-4957)
1008048* - NTP Mrulist Malicious Query Denial Of Service Vulnerability (CVE-2016-7434)


Novell GroupWise Admin Service
1006822* - Novell Groupwise "poLibMaintenanceFileSave" Security Bypass Vulnerability


SSL Client
1008088 - GnuTLS Libtasn1 ASN.1 DER Infinite Loop Denial Of Service Vulnerability (CVE-2016-4008) - Client


SSL/TLS Server
1008089 - GnuTLS Libtasn1 ASN.1 DER Infinite Loop Denial Of Service Vulnerability (CVE-2016-4008) - Server


Suspicious Client Ransomware Activity
1007704* - Ransomware Network Traffic - 1


Web Application Common
1008050 - ImageMagick Out Of Bounds Array Indexing Denial Of Service Vulnerability (CVE-2016-7799)
1008046 - ImageMagick SGI Coder Out Of Bounds Read Vulnerability (CVE-2016-7101)


Web Application PHP Based
1008096 - Identified Drupal Core system.temporary Information Disclosure Vulnerability
1008118 - Identified Suspicious Upload Of WordPress Plugin
1008038* - PHP GC ZipArchive Class Use After Free Vulnerability (CVE-2016-5773)


Web Client Common
1008049 - ImageMagick Out Of Bounds Array Indexing Denial Of Service Vulnerability (CVE-2016-7799) - 1
1008047 - ImageMagick SGI Coder Out Of Bounds Read Vulnerability (CVE-2016-7101) - 1
1007427* - Microsoft Windows DLL Loading Vulnerabilities Over WebDAV (MS16-014)
1008067* - Microsoft Windows Uniscribe Remote Code Execution Vulnerability (CVE-2016-7274)


Web Server Miscellaneous
1008001* - MongoDB Javascript Injection Collection Enumeration Vulnerability


Integrity Monitoring Rules:

There are no new or updated Integrity Monitoring Rules in this Security Update.


Log Inspection Rules:

1003802* - Directory Server – Microsoft Windows Active Directory