Cisco Talos (VRT) Update for Sourcefire 3D System

* Talos combines our security experts from TRAC, SecApps, and VRT teams.

Date: 2017-04-20

This SRU number: 2017-04-19-002
Previous SRU number: 2017-04-19-001

Applies to:

This SEU number: 1659
Previous SEU: 1658

Applies to:

This is the complete list of rules added in SRU 2017-04-19-002 and SEU 1659.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
142292INDICATOR-COMPROMISEmalicious javascript obfuscation detectedoffoffoff
142294OS-WINDOWSMicrosoft Windows SMBv1 WriteAndX and TransSecondaryRequest TotalDataCount out of bounds write attemptoffoffdrop
142296FILE-PDFAdobe Acrobat Reader malformed PRC file out of bounds read attemptoffdropdrop
142297FILE-PDFAdobe Acrobat Reader malformed PRC file out of bounds read attemptoffdropdrop
142298FILE-PDFAdobe PDF PPKLite security handler memory corruption vulnerability attemptoffoffdrop
142299FILE-PDFAdobe PDF PPKLite security handler memory corruption vulnerability attemptoffoffdrop
142300SERVER-WEBAPPSensorIP2 default credentials enumeration attemptoffoffoff
142301MALWARE-CNCWin.Trojan.Kuaibu inbound server configuration responseoffdropdrop
142302MALWARE-CNCWin.Trojan.Kuaibu outbound connection attemptoffdropdrop
142303MALWARE-CNCWin.Trojan.Kuaibu outbound file download attemptoffdropdrop
142304FILE-OTHERfwpuclnt dll-load exploit attemptoffoffoff
142305FILE-OTHERfwpuclnt dll-load exploit attemptoffoffoff
142307FILE-PDFAdobe Acrobat Reader malformed TTF out of bounds memory access attemptoffoffoff
142308FILE-PDFAdobe Acrobat Reader malformed TTF out of bounds memory access attemptoffoffoff
142309FILE-PDFAdobe Acrobat embedded JPEG2000 invalid header out of bounds memory access attemptoffdropdrop
142310FILE-PDFAdobe Acrobat embedded JPEG2000 invalid header out of bounds memory access attemptoffdropdrop
142311FILE-PDFAdobe Acrobat Reader malformed JP2K codestream out of bounds read attemptoffoffdrop
142312FILE-PDFAdobe Acrobat Reader malformed JP2K codestream out of bounds read attemptoffoffdrop
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
342293PROTOCOL-VOIPCisco Unified Communications Manager SIP NOTIFY denial of service attemptoffoffoff
142295SERVER-WEBAPPEvents HMI information disclosure attemptoffoffoff
142306SERVER-WEBAPPxArrow webserver denial of service attemptoffoffoff

Updated Rules:

Updated rules can be found at this link.