Rule Update
18-032 (June 12, 2018)
Publish date: June 13, 2018
DESCRIPTION
* indicates a new version of an existing rule
Deep Packet Inspection Rules:
DNS Client
1009059* - ISC BIND DNS Denial Of Service Vulnerability (CVE-2017-3145)
1009135 - Microsoft Windows DNSAPI Remote Code Execution Vulnerability (CVE-2018-8225)
Elasticsearch Java API Protocol
1008685* - Elastic Elasticsearch ThrowableObjectInputStream Insecure Deserialization (CVE-2015-5377)
HP Intelligent Management Center (IMC)
1008905* - HPE Intelligent Management Center 'UrlAccessController' Authentication Bypass Vulnerability (CVE-2017-8982)
1008969* - HPE Intelligent Management Center Multiple Expression Language Injection Vulnerability
Microsoft Office
1009138 - Microsoft Excel Remote Code Execution Vulnerability (CVE-2018-8248)
SIP SSL Client
1008554 - Digium Asterisk TLS Certificate Validation Security Bypass Vulnerability (CVE-2015-3008)
Trend Micro Control Manager
1008721* - Trend Micro Control Manager cmdHandlerStatusMonitor SQL Injection Vulnerability (CVE-2017-11385)
Trend Micro OfficeScan
1008191* - Trend Micro Smart Protection Server Authenticated Remote Code Execution Vulnerabilities
VoIP Soft Phones
1008653 - Digium Asterisk Non-SIP URIs Denial Of Service Vulnerability (CVE-2017-14098)
Web Application Common
1009041* - ImageMagick 'ReadDCMImage' Denial Of Service Vulnerability (CVE-2018-6405) - 1
1009038* - ImageMagick 'ReadMATImage' Denial Of Service Vulnerability (CVE-2017-13658) - 1
1008974* - ImageMagick 'ReadMATImage' Denial Of Service Vulnerability (CVE-2017-18029) - 1
1008990* - ImageMagick 'ReadMATImage' Information Disclosure Vulnerability (CVE-2017-13143) - 1
1008992* - ImageMagick 'ReadOneJNGImage' Denial Of Service Vulnerability (CVE-2017-11750) - 1
1008996* - ImageMagick 'ReadPSDImage' Denial Of Service Vulnerability (CVE-2017-13061) - 1
1009090* - ImageMagick ReadOneMNGImage Denial Of Service Vulnerability (CVE-2018-10177) - 1
1008994* - ImageMagick ReadOnePNGImage Memory Leak Vulnerability (CVE-2017-13141) - 1
1008980* - ImageMagick Use-After-Free Vulnerability (CVE-2017-17499) - 1
Web Application PHP Based
1008894* - PHP 'wddx_stack_destroy' Function Use After Free Vulnerability (CVE-2016-7413)
1008914 - PHP WDDX Deserialization Denial Of Service Vulnerability (CVE-2017-11143)
1008913 - PHP WDDX Deserialization Heap Out-Of-Bound Read Vulnerability (CVE-2017-11145)
Web Client Common
1009104 - Adobe Acrobat Reader Out Of Bounds Read Vulnerability (CVE-2017-16397)
1009102 - Adobe Acrobat Reader Out Of Bounds Read Vulnerability (CVE-2017-16404)
1009146 - Adobe Flash Player Multiple Security Vulnerabilities (APSB18-19)
1008829* - Foxit Reader Multiple Information Disclosure Vulnerabilities
1009014* - Microsoft Windows Graphics Multiple Security Vulnerabilities (Apr-2018)
1009140 - Microsoft Windows Media Foundation Memory Corruption Vulnerability (CVE-2018-8251)
1009131 - Microsoft Windows Multiple Elevation Of Privilege Vulnerabilities (June-2018)
1009134 - Microsoft Windows Remote Code Execution Vulnerability (CVE-2018-8210)
1009044 - Multiple Web Browser WebRTC Private IP Leakage To WebPage Vulnerability (CVE-2018-6849)
Web Client Internet Explorer/Edge
1009132 - Microsoft Edge Memory Corruption Vulnerability (CVE-2018-8110)
1009133 - Microsoft Edge Memory Corruption Vulnerability (CVE-2018-8111)
1009137 - Microsoft Edge Memory Corruption Vulnerability (CVE-2018-8236)
1009136 - Microsoft Edge Scripting Engine Memory Corruption Vulnerability (CVE-2018-8229)
1009130 - Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2018-0978)
1009139 - Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2018-8249)
1009141 - Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability (CVE-2018-8267)
Web Server Adobe ColdFusion
1008879* - Adobe Coldfusion BlazeDS Java Object Deserialization Remote Code Execution Vulnerability (CVE-2017-3066)
Web Server Apache
1009087* - Apache httpd FilesMatch Directive Security Restriction Bypass Vulnerability (CVE-2017-15715)
Integrity Monitoring Rules:
1008720* - Users and Groups - Create and Delete Activity
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
Deep Packet Inspection Rules:
DNS Client
1009059* - ISC BIND DNS Denial Of Service Vulnerability (CVE-2017-3145)
1009135 - Microsoft Windows DNSAPI Remote Code Execution Vulnerability (CVE-2018-8225)
Elasticsearch Java API Protocol
1008685* - Elastic Elasticsearch ThrowableObjectInputStream Insecure Deserialization (CVE-2015-5377)
HP Intelligent Management Center (IMC)
1008905* - HPE Intelligent Management Center 'UrlAccessController' Authentication Bypass Vulnerability (CVE-2017-8982)
1008969* - HPE Intelligent Management Center Multiple Expression Language Injection Vulnerability
Microsoft Office
1009138 - Microsoft Excel Remote Code Execution Vulnerability (CVE-2018-8248)
SIP SSL Client
1008554 - Digium Asterisk TLS Certificate Validation Security Bypass Vulnerability (CVE-2015-3008)
Trend Micro Control Manager
1008721* - Trend Micro Control Manager cmdHandlerStatusMonitor SQL Injection Vulnerability (CVE-2017-11385)
Trend Micro OfficeScan
1008191* - Trend Micro Smart Protection Server Authenticated Remote Code Execution Vulnerabilities
VoIP Soft Phones
1008653 - Digium Asterisk Non-SIP URIs Denial Of Service Vulnerability (CVE-2017-14098)
Web Application Common
1009041* - ImageMagick 'ReadDCMImage' Denial Of Service Vulnerability (CVE-2018-6405) - 1
1009038* - ImageMagick 'ReadMATImage' Denial Of Service Vulnerability (CVE-2017-13658) - 1
1008974* - ImageMagick 'ReadMATImage' Denial Of Service Vulnerability (CVE-2017-18029) - 1
1008990* - ImageMagick 'ReadMATImage' Information Disclosure Vulnerability (CVE-2017-13143) - 1
1008992* - ImageMagick 'ReadOneJNGImage' Denial Of Service Vulnerability (CVE-2017-11750) - 1
1008996* - ImageMagick 'ReadPSDImage' Denial Of Service Vulnerability (CVE-2017-13061) - 1
1009090* - ImageMagick ReadOneMNGImage Denial Of Service Vulnerability (CVE-2018-10177) - 1
1008994* - ImageMagick ReadOnePNGImage Memory Leak Vulnerability (CVE-2017-13141) - 1
1008980* - ImageMagick Use-After-Free Vulnerability (CVE-2017-17499) - 1
Web Application PHP Based
1008894* - PHP 'wddx_stack_destroy' Function Use After Free Vulnerability (CVE-2016-7413)
1008914 - PHP WDDX Deserialization Denial Of Service Vulnerability (CVE-2017-11143)
1008913 - PHP WDDX Deserialization Heap Out-Of-Bound Read Vulnerability (CVE-2017-11145)
Web Client Common
1009104 - Adobe Acrobat Reader Out Of Bounds Read Vulnerability (CVE-2017-16397)
1009102 - Adobe Acrobat Reader Out Of Bounds Read Vulnerability (CVE-2017-16404)
1009146 - Adobe Flash Player Multiple Security Vulnerabilities (APSB18-19)
1008829* - Foxit Reader Multiple Information Disclosure Vulnerabilities
1009014* - Microsoft Windows Graphics Multiple Security Vulnerabilities (Apr-2018)
1009140 - Microsoft Windows Media Foundation Memory Corruption Vulnerability (CVE-2018-8251)
1009131 - Microsoft Windows Multiple Elevation Of Privilege Vulnerabilities (June-2018)
1009134 - Microsoft Windows Remote Code Execution Vulnerability (CVE-2018-8210)
1009044 - Multiple Web Browser WebRTC Private IP Leakage To WebPage Vulnerability (CVE-2018-6849)
Web Client Internet Explorer/Edge
1009132 - Microsoft Edge Memory Corruption Vulnerability (CVE-2018-8110)
1009133 - Microsoft Edge Memory Corruption Vulnerability (CVE-2018-8111)
1009137 - Microsoft Edge Memory Corruption Vulnerability (CVE-2018-8236)
1009136 - Microsoft Edge Scripting Engine Memory Corruption Vulnerability (CVE-2018-8229)
1009130 - Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2018-0978)
1009139 - Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2018-8249)
1009141 - Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability (CVE-2018-8267)
Web Server Adobe ColdFusion
1008879* - Adobe Coldfusion BlazeDS Java Object Deserialization Remote Code Execution Vulnerability (CVE-2017-3066)
Web Server Apache
1009087* - Apache httpd FilesMatch Directive Security Restriction Bypass Vulnerability (CVE-2017-15715)
Integrity Monitoring Rules:
1008720* - Users and Groups - Create and Delete Activity
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
Featured Stories
- Unveiling AI Agent Vulnerabilities Part V: Securing LLM ServicesTo conclude our series on agentic AI, this article examines emerging vulnerabilities that threaten AI agents, focusing on providing proactive security recommendations on areas such as code execution, data exfiltration, and database access.Read more
- Unveiling AI Agent Vulnerabilities Part IV: Database Access VulnerabilitiesHow can attackers exploit weaknesses in database-enabled AI agents? This research explores how SQL generation vulnerabilities, stored prompt injection, and vector store poisoning can be weaponized by attackers for fraudulent activities.Read more
- The Mirage of AI Programming: Hallucinations and Code IntegrityThe adoption of large language models (LLMs) and Generative Pre-trained Transformers (GPTs), such as ChatGPT, by leading firms like Microsoft, Nuance, Mix and Google CCAI Insights, drives the industry towards a series of transformative changes. As the use of these new technologies becomes prevalent, it is important to understand their key behavior, advantages, and the risks they present.Read more
- Open RAN: Attack of the xAppsThis article discusses two O-RAN vulnerabilities that attackers can exploit. One vulnerability stems from insufficient access control, and the other arises from faulty message handlingRead more