Cisco Talos (VRT) Update for Sourcefire 3D System

* Talos combines our security experts from TRAC, SecApps, and VRT teams.

Date: 2017-03-14

This SRU number: 2017-03-14-002
Previous SRU number: 2017-03-09-002

Applies to:

This SEU number: 1629
Previous SEU: 1627

Applies to:

This is the complete list of rules modified in SRU 2017-03-14-002 and SEU 1629.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

Updated Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
133469FILE-FLASHAdobe Flash Player PCRE regex compilation memory corruption attemptoffdropdrop
133470FILE-FLASHAdobe Flash Player PCRE regex compilation memory corruption attemptoffdropdrop
140364BROWSER-IEMicrosoft Internet Explorer loadXML parseError.errorCode information disclosure attemptoffoffdrop
140365BROWSER-IEMicrosoft Internet Explorer loadXML parseError.errorCode information disclosure attemptoffoffdrop
140394OS-WINDOWSMicrosoft Windows Ntoskrnl integer overflow privilege escalation attemptoffdropdrop
140395OS-WINDOWSMicrosoft Windows Ntoskrnl integer overflow privilege escalation attemptoffdropdrop
141553BROWSER-IEMicrosoft Edge url forgery attemptoffdropdrop
141554BROWSER-IEMicrosoft Edge url forgery attemptoffdropdrop
141557BROWSER-IEMicrosoft Edge Array out of bounds memory corruption attemptoffdropdrop
141558BROWSER-IEMicrosoft Edge Array out of bounds memory corruption attemptoffdropdrop
141559BROWSER-IEMicrosoft Edge Array out of bounds memory corruption attemptoffdropdrop
141560BROWSER-IEMicrosoft Edge Array out of bounds memory corruption attemptoffdropdrop
141561BROWSER-IEMicrosoft Internet Explorer array proto chain manipulation memory corruption attemptoffdropdrop
141562BROWSER-IEMicrosoft Internet Explorer array proto chain manipulation memory corruption attemptoffdropdrop
141563FILE-OFFICEMicrosoft Office imjp12k.dll dll-load exploit attemptoffoffoff
141564FILE-OFFICEMicrosoft Office imjp12k.dll dll-load exploit attemptoffoffoff
141565FILE-OFFICEMicrosoft Office Excel xlsb use-after-free attemptoffdropdrop
141566FILE-OFFICEMicrosoft Office Excel xlsb use-after-free attemptoffdropdrop
141567OS-WINDOWSMicrosoft Windows Device Guard code execution attemptoffdropdrop
141568OS-WINDOWSMicrosoft Windows Device Guard code execution attemptoffdropdrop
141569OS-WINDOWSMicrosoft Windows Device Guard code execution attemptoffdropdrop
141570OS-WINDOWSMicrosoft Windows Device Guard code execution attemptoffdropdrop
141571OS-WINDOWSMicrosoft Windows Device Guard code execution attemptoffdropdrop
141572OS-WINDOWSMicrosoft Windows Device Guard code execution attemptoffdropdrop
141575BROWSER-IEMicrosoft Internet Explorer mhtml and res protocol information disclosure attemptoffoffoff
141576BROWSER-IEMicrosoft Internet Explorer mhtml and res protocol information disclosure attemptoffoffoff
141577FILE-OFFICEMicrosoft Office RTF footnote format use after free attemptoffdropdrop
141578FILE-OFFICEMicrosoft Office RTF footnote format use after free attemptoffdropdrop
141579OS-WINDOWSMicrosoft Windows DirectComposition double free attemptoffdropdrop
141580OS-WINDOWSMicrosoft Windows DirectComposition double free attemptoffdropdrop
141581FILE-OFFICEMicrosoft Excel malformed CellXF memory corruption attemptoffoffdrop
141582FILE-OFFICEMicrosoft Excel malformed CellXF memory corruption attemptoffoffdrop
141583BROWSER-IEMicrosoft Internet Explorer DOMAttrModified event use after free attemptoffdropdrop
141584BROWSER-IEMicrosoft Internet Explorer DOMAttrModified event use after free attemptoffdropdrop
141585BROWSER-IEMicrosoft Internet Explorer mutated scope with generator memory corruption attemptoffoffdrop
141586BROWSER-IEMicrosoft Internet Explorer mutated scope with generator memory corruption attemptoffoffdrop
141587BROWSER-IEMicrosoft Internet Explorer Array out of bounds memory corruptionoffdropdrop
141588BROWSER-IEMicrosoft Internet Explorer Array out of bounds memory corruptionoffdropdrop
141589BROWSER-IEMicrosoft Internet Explorer CHtmlTab use after free attemptoffdropdrop
141590BROWSER-IEMicrosoft Internet Explorer CHtmlTab use after free attemptoffdropdrop
141591OS-WINDOWSMicrosoft Windows GDI privilege escalation attemptoffdropdrop
141592OS-WINDOWSMicrosoft Windows GDI privilege escalation attemptoffdropdrop
141593BROWSER-IEMicrosoft Edge Data URI same origin policy bypass attemptoffoffoff
141594BROWSER-IEMicrosoft Edge Data URI same origin policy bypass attemptoffoffoff
141597FILE-OTHERWindows Uniscribe remote code execution vulnerability attemptoffoffdrop
141598FILE-OTHERWindows Uniscribe remote code execution vulnerability attemptoffoffdrop
141601FILE-PDFMicrosoft Edge PDF Builder out of bounds read attemptoffdropdrop
141602FILE-PDFMicrosoft Edge PDF Builder out of bounds read attemptoffdropdrop
141607OS-WINDOWSMicrosoft Windows Kernel NtCreateProfile privilege escalation attemptoffoffdrop
141608OS-WINDOWSMicrosoft Windows Kernel NtCreateProfile privilege escalation attemptoffoffdrop
141609OS-WINDOWSMicrosoft Windows Kernel NtCreateProfile privilege escalation attemptoffoffdrop
141610OS-WINDOWSMicrosoft Windows Kernel NtCreateProfile privilege escalation attemptoffoffdrop
141625BROWSER-IEMicrosoft Edge HandleColumnBreakOnColumnSpanningElement type confusion attemptoffdropdrop
141626BROWSER-IEMicrosoft Edge HandleColumnBreakOnColumnSpanningElement type confusion attemptoffdropdrop
141895BROWSER-IEMicrosoft Internet Explorer frameset null pointer dereference attemptoffoffoff
141896BROWSER-IEMicrosoft Internet Explorer frameset null pointer dereference attemptoffoffoff
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
141573BROWSER-IEMicrosoft Edge CSS animation style information disclosure attemptoffdropdrop
141574BROWSER-IEMicrosoft Edge CSS animation style information disclosure attemptoffdropdrop
141605BROWSER-IEMicrosoft Edge AsmJs memory corruption attemptoffoffdrop
141606BROWSER-IEMicrosoft Edge AsmJs memory corruption attemptoffoffdrop
141633BROWSER-IEMicrosoft Internet Explorer 11 Windows Media Player information disclosure attemptoffoffoff
141634BROWSER-IEMicrosoft Internet Explorer 11 Windows Media Player information disclosure attemptoffoffoff