Cisco Talos Update for FireSIGHT Management Center

Date: 2019-08-13

This SRU number: 2019-08-12-001
Previous SRU number: 2019-08-07-001

Applies to:

This SEU number: 2053
Previous SEU: 2051

Applies to:

This is the complete list of rules modified in SRU 2019-08-12-001 and SEU 2053.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Cisco Talos policy, Connectivity, Balanced, Security, and Maximum Detection.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

Updated Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
115539FILE-OFFICEMicrosoft Office Excel Formula record remote code execution attemptoffoffoffdrop
11807POLICY-OTHERChunked-Encoding transfer with no data attemptoffoffoffdrop
118632FILE-OFFICEMicrosoft Office Excel malformed Label record exploit attemptoffoffoffdrop
118637FILE-OFFICEMicrosoft Office PowerPoint OfficeArt atom memory corruption attemptoffoffoffdrop
132940FILE-OFFICEMicrosoft Office Excel malformed Label record exploit attemptoffoffoffdrop
135190FILE-OFFICEMicrosoft Office Word sprmPItap heap corruption attemptoffoffdropdrop
135191FILE-OFFICEMicrosoft Office Word sprmPItap heap corruption attemptoffoffdropdrop
138265FILE-OFFICEMicrosoft Office Excel Formula record remote code execution attemptoffoffoffdrop
145142BROWSER-IEMicrosoft Edge type confusion attemptoffdropdropdrop
145143BROWSER-IEMicrosoft Edge type confusion attemptoffdropdropdrop
147576SERVER-WEBAPPCobub Razor channel name SQL injection attemptoffoffdropdrop
147577SERVER-WEBAPPCobub Razor channel name SQL injection attemptoffoffdropdrop
148051BROWSER-IEMicrosoft Edge OP_Memset type confusion attemptoffoffdropdrop
148052BROWSER-IEMicrosoft Edge OP_Memset type confusion attemptoffoffdropdrop
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
11826SERVER-WEBAPPWEB-INF accessoffoffoffdrop
150920SERVER-WEBAPPSynology Photo Station information disclosure attemptoffoffoffdrop