Rule Update
24-021 (April 23, 2024)
Publish date: April 23, 2024
DESCRIPTION
* indicates a new version of an existing rule
Deep Packet Inspection Rules:
Arcserve Unified Data Protection
1012019 - Arcserve Unified Data Protection Denial of Service Vulnerability (CVE-2024-0801)
1011972* - Arcserve Unified Data Protection Directory Traversal Vulnerability (CVE-2023-42000)
1011970* - Arcserve Unified Data Protection Remote Code Execution Vulnerability (CVE-2023-41998)
DCERPC Services
1004600* - Microsoft Active Directory 'BROWSER ELECTION' Buffer Overflow Vulnerability
1005140* - Print Spooler Service Format String Vulnerability (CVE-2012-1851)
1004401* - Print Spooler Service Impersonation Vulnerability
1004346* - SMB Pool Overflow Vulnerability
1004355* - SMB Stack Exhaustion Vulnerability
1004641* - SMB Transaction Parsing Vulnerability (CVE-2011-0661)
1004348* - SMB Variable Validation Vulnerability
DCERPC Services - Client
1004821* - Active Accessibility Insecure Library Loading Vulnerability (CVE-2011-1247)
1004700* - DFS Memory Corruption Vulnerability (CVE-2011-1868)
1004762* - Data Access Components Insecure Library Loading Vulnerability Over Network Share (CVE-2011-1975)
1004563* - Microsoft Windows 'CreateSizedDIBSECTION()' Thumbnail View Stack Buffer Overflow Vulnerability Over Network Share
1004697* - OLE Automation Underflow Vulnerability ( CVE-2011-0658 )
1004897* - Object Packager Insecure Executable Launching Vulnerability Over Network Share (CVE-2012-0009)
1004877* - PowerPoint Insecure Library Loading Vulnerability Over Network Share (CVE-2011-3396)
1005139* - Remote Administration Protocol Denial Of Service Vulnerability (CVE-2012-1850)
1004100* - SMB Client Message Size Vulnerability
1004637* - SMB Client Response Parsing Vulnerability (CVE-2011-0660)
1004692* - SMB Response Parsing Vulnerability (CVE-2011-1268)
1004775* - Telnet Handler Remote Code Execution Vulnerability Over Network Share (CVE-2011-1961)
1005081* - Vulnerability In Windows Shell Could Allow Remote Code Execution (CVE-2012-0175)
1004797* - Windows Components Insecure Library Loading Vulnerability Over Network Share (CVE-2011-1991)
1004843* - Windows Mail Insecure Library Loading Vulnerability Over Network Share (CVE-2011-2016)
Elastic Kibana And Elasticsearch
1011909* - Elastic Kibana Upgrade Assistant Telemetry Collector Prototype Pollution Vulnerability
HP Intelligent Management Center (IMC)
1011941* - Apache OFBiz Insecure Deserialization Vulnerability (CVE-2023-49070)
JetBrains TeamCity
1012020 - JetBrains TeamCity Cross-Site Scripting Vulnerability (CVE-2024-31138)
Link-Local Multicast Name Resolution
1004645* - DNS Query Vulnerability (CVE-2011-0657)
Nextgen Mirth Connect
1012008 - Nextgen Mirth Connect Insecure Deserialization Vulnerability (CVE-2023-43208)
Remote Desktop Protocol Server
1004949* - Remote Desktop Protocol Vulnerability (CVE-2012-0002)
1005138* - Remote Desktop Protocol Vulnerability (CVE-2012-2526)
Web Server Miscellaneous
1012026 - CrushFTP Remote Code Execution Vulnerability (CVE-2023-43177)
1012017 - Identified Restricted file upload with specific extension
Web Server Squid
1011939* - Squid Proxy Heap Buffer Overflow Vulnerability (CVE-2023-46847)
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
Deep Packet Inspection Rules:
Arcserve Unified Data Protection
1012019 - Arcserve Unified Data Protection Denial of Service Vulnerability (CVE-2024-0801)
1011972* - Arcserve Unified Data Protection Directory Traversal Vulnerability (CVE-2023-42000)
1011970* - Arcserve Unified Data Protection Remote Code Execution Vulnerability (CVE-2023-41998)
DCERPC Services
1004600* - Microsoft Active Directory 'BROWSER ELECTION' Buffer Overflow Vulnerability
1005140* - Print Spooler Service Format String Vulnerability (CVE-2012-1851)
1004401* - Print Spooler Service Impersonation Vulnerability
1004346* - SMB Pool Overflow Vulnerability
1004355* - SMB Stack Exhaustion Vulnerability
1004641* - SMB Transaction Parsing Vulnerability (CVE-2011-0661)
1004348* - SMB Variable Validation Vulnerability
DCERPC Services - Client
1004821* - Active Accessibility Insecure Library Loading Vulnerability (CVE-2011-1247)
1004700* - DFS Memory Corruption Vulnerability (CVE-2011-1868)
1004762* - Data Access Components Insecure Library Loading Vulnerability Over Network Share (CVE-2011-1975)
1004563* - Microsoft Windows 'CreateSizedDIBSECTION()' Thumbnail View Stack Buffer Overflow Vulnerability Over Network Share
1004697* - OLE Automation Underflow Vulnerability ( CVE-2011-0658 )
1004897* - Object Packager Insecure Executable Launching Vulnerability Over Network Share (CVE-2012-0009)
1004877* - PowerPoint Insecure Library Loading Vulnerability Over Network Share (CVE-2011-3396)
1005139* - Remote Administration Protocol Denial Of Service Vulnerability (CVE-2012-1850)
1004100* - SMB Client Message Size Vulnerability
1004637* - SMB Client Response Parsing Vulnerability (CVE-2011-0660)
1004692* - SMB Response Parsing Vulnerability (CVE-2011-1268)
1004775* - Telnet Handler Remote Code Execution Vulnerability Over Network Share (CVE-2011-1961)
1005081* - Vulnerability In Windows Shell Could Allow Remote Code Execution (CVE-2012-0175)
1004797* - Windows Components Insecure Library Loading Vulnerability Over Network Share (CVE-2011-1991)
1004843* - Windows Mail Insecure Library Loading Vulnerability Over Network Share (CVE-2011-2016)
Elastic Kibana And Elasticsearch
1011909* - Elastic Kibana Upgrade Assistant Telemetry Collector Prototype Pollution Vulnerability
HP Intelligent Management Center (IMC)
1011941* - Apache OFBiz Insecure Deserialization Vulnerability (CVE-2023-49070)
JetBrains TeamCity
1012020 - JetBrains TeamCity Cross-Site Scripting Vulnerability (CVE-2024-31138)
Link-Local Multicast Name Resolution
1004645* - DNS Query Vulnerability (CVE-2011-0657)
Nextgen Mirth Connect
1012008 - Nextgen Mirth Connect Insecure Deserialization Vulnerability (CVE-2023-43208)
Remote Desktop Protocol Server
1004949* - Remote Desktop Protocol Vulnerability (CVE-2012-0002)
1005138* - Remote Desktop Protocol Vulnerability (CVE-2012-2526)
Web Server Miscellaneous
1012026 - CrushFTP Remote Code Execution Vulnerability (CVE-2023-43177)
1012017 - Identified Restricted file upload with specific extension
Web Server Squid
1011939* - Squid Proxy Heap Buffer Overflow Vulnerability (CVE-2023-46847)
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
Featured Stories
- Unveiling AI Agent Vulnerabilities Part V: Securing LLM ServicesTo conclude our series on agentic AI, this article examines emerging vulnerabilities that threaten AI agents, focusing on providing proactive security recommendations on areas such as code execution, data exfiltration, and database access.Read more
- Unveiling AI Agent Vulnerabilities Part IV: Database Access VulnerabilitiesHow can attackers exploit weaknesses in database-enabled AI agents? This research explores how SQL generation vulnerabilities, stored prompt injection, and vector store poisoning can be weaponized by attackers for fraudulent activities.Read more
- The Mirage of AI Programming: Hallucinations and Code IntegrityThe adoption of large language models (LLMs) and Generative Pre-trained Transformers (GPTs), such as ChatGPT, by leading firms like Microsoft, Nuance, Mix and Google CCAI Insights, drives the industry towards a series of transformative changes. As the use of these new technologies becomes prevalent, it is important to understand their key behavior, advantages, and the risks they present.Read more
- Open RAN: Attack of the xAppsThis article discusses two O-RAN vulnerabilities that attackers can exploit. One vulnerability stems from insufficient access control, and the other arises from faulty message handlingRead more