Cisco Talos (VRT) Update for Sourcefire 3D System

* Talos combines our security experts from TRAC, SecApps, and VRT teams.

Date: 2017-11-14

This SRU number: 2017-11-13-001
Previous SRU number: 2017-11-09-001

Applies to:

This SEU number: 1757
Previous SEU: 1756

Applies to:

This is the complete list of rules added in SRU 2017-11-13-001 and SEU 1757.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Sourcefire policy, Connectivity, Balanced and Security.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
144809BROWSER-IEMicrosoft Edge postMessage use after free attemptoffdropdrop
144810BROWSER-IEMicrosoft Edge postMessage use after free attemptoffdropdrop
144811BROWSER-IEMicrosoft Edge scripting engine type confusion attemptoffdropdrop
144812BROWSER-IEMicrosoft Edge scripting engine type confusion attemptoffdropdrop
144813BROWSER-IEMicrosoft Edge Chakra Closure use after free attemptoffdropdrop
144814BROWSER-IEMicrosoft Edge Chakra Closure use after free attemptoffdropdrop
144815BROWSER-IEMicrosoft Edge use after free attemptoffoffdrop
144816BROWSER-IEMicrosoft Edge use after free attemptoffoffdrop
144817BROWSER-IEMicrosoft Edge custom property memory corruption attemptoffdropdrop
144818BROWSER-IEMicrosoft Edge custom property memory corruption attemptoffdropdrop
144819BROWSER-IEMicrosoft Edge array use after free attemptoffdropdrop
144820BROWSER-IEMicrosoft Edge array use after free attemptoffdropdrop
144821FILE-OFFICEMicrosoft Excel use after free vulnerability exploit attemptoffoffdrop
144822FILE-OFFICEMicrosoft Excel use after free vulnerability exploit attemptoffoffdrop
144823BROWSER-IEMicrosoft Internet Explorer VBScript Join out of bounds memory access attemptoffoffoff
144824BROWSER-IEMicrosoft Internet Explorer VBScript Join out of bounds memory access attemptoffoffoff
144825OS-WINDOWSMicrosoft Edge out of bounds write attemptoffoffoff
144826OS-WINDOWSMicrosoft Edge out of bounds write attemptoffoffoff
144827BROWSER-IEMicrosoft Edge scripting engine memory corruption attemptoffdropdrop
144828BROWSER-IEMicrosoft Edge scripting engine memory corruption attemptoffdropdrop
144829BROWSER-IEMicrosoft Internet Explorer array memory corruption attemptoffdropdrop
144830BROWSER-IEMicrosoft Internet Explorer array memory corruption attemptoffdropdrop
144831BROWSER-IEMicrosoft Edge memory corruption exploitation attemptoffdropdrop
144832BROWSER-IEMicrosoft Edge memory corruption exploitation attemptoffdropdrop
144833OS-WINDOWSMicrosoft Windows win32k.sys use after free attemptoffdropdrop
144834OS-WINDOWSMicrosoft Windows win32k.sys use after free attemptoffdropdrop
344835SERVER-WEBAPPTRUFFLEHUNTER TALOS-2017-0472 attack attemptoffoffdrop
344836SERVER-WEBAPPTRUFFLEHUNTER TALOS-2017-0472 attack attemptoffoffdrop
344837SERVER-WEBAPPTRUFFLEHUNTER TALOS-2017-0472 attack attemptoffoffdrop
144838FILE-OFFICEMicrosoft Word RTF memory corruption attemptoffoffoff
144839FILE-OFFICEMicrosoft Word RTF memory corruption attemptoffoffoff
344840SERVER-WEBAPPTRUFFLEHUNTER TALOS-2017-0473 attack attemptoffoffdrop
344841SERVER-WEBAPPTRUFFLEHUNTER TALOS-2017-0473 attack attemptoffoffdrop
344842SERVER-WEBAPPTRUFFLEHUNTER TALOS-2017-0473 attack attemptoffoffdrop
144843BROWSER-IEMicrosoft Edge Uint8Array memory corruption attemptoffoffoff
144844BROWSER-IEMicrosoft Edge Uint8Array memory corruption attemptoffoffoff
144845BROWSER-IEMicrosoft Edge heap overflow attemptoffdropdrop
144846BROWSER-IEMicrosoft Edge heap overflow attemptoffdropdrop
344847SERVER-WEBAPPTRUFFLEHUNTER TALOS-2017-0482 attack attemptoffoffdrop
344848SERVER-WEBAPPTRUFFLEHUNTER TALOS-2017-0482 attack attemptoffoffdrop
344849SERVER-WEBAPPTRUFFLEHUNTER TALOS-2017-0482 attack attemptoffoffdrop
344850SERVER-WEBAPPTRUFFLEHUNTER TALOS-2017-0477 attack attemptoffoffdrop
344851SERVER-WEBAPPTRUFFLEHUNTER TALOS-2017-0477 attack attemptoffoffdrop
344852SERVER-WEBAPPTRUFFLEHUNTER TALOS-2017-0477 attack attemptoffoffdrop
144853FILE-PDFAdobe Acrobat Reader malformed TTF buffer over-read attemptoffoffdrop
144854FILE-PDFAdobe Acrobat Reader malformed TTF buffer over-read attemptoffoffdrop
344855POLICY-OTHERTRUFFLEHUNTER TALOS-2017-0480 attack attemptoffoffoff
144856FILE-PDFAdobe Acrobat Reader XI JavaScript annotation use after free attemptoffdropdrop
144857FILE-PDFAdobe Acrobat Reader XI JavaScript annotation use after free attemptoffdropdrop
144859FILE-OTHERAdobe Acrobat Pro PNG file buffer over-read vulnerability attemptoffoffdrop
144860FILE-OTHERAdobe Acrobat Pro PNG file buffer over-read vulnerability attemptoffoffdrop
144861FILE-IMAGEAdobe Acrobat Pro malformed CommentExtension attemptoffdropdrop
144862FILE-IMAGEAdobe Acrobat Pro malformed CommentExtension attemptoffdropdrop
344863SERVER-WEBAPPTRUFFLEHUNTER TALOS-2017-0483 attack attemptoffoffdrop
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.
144808INDICATOR-COMPROMISEApache HTTP Server possible mod_dav.c remote denial of service vulnerability attemptoffoffoff
344858SERVER-WEBAPPTRUFFLEHUNTER TALOS-2017-0474 attack attemptoffoffdrop

Updated Rules:

Updated rules can be found at this link.