Cisco Talos Update for FireSIGHT Management Center

Date: 2019-08-13

This SRU number: 2019-08-12-001
Previous SRU number: 2019-08-07-001

Applies to:

This SEU number: 2053
Previous SEU: 2051

Applies to:

This is the complete list of rules added in SRU 2019-08-12-001 and SEU 2053.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Cisco Talos policy, Connectivity, Balanced, Security, and Maximum Detection.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
150936OS-WINDOWSMicrosoft Windows shell privilege escalation attemptoffdropdropdrop
150937OS-WINDOWSMicrosoft Windows shell privilege escalation attemptoffdropdropdrop
150938BROWSER-IEMicrosoft Edge scripting engine memory corruption vulnerability attemptoffdropdropdrop
150939BROWSER-IEMicrosoft Edge scripting engine memory corruption vulnerability attemptoffdropdropdrop
150940BROWSER-IEMicrosoft Edge scripting engine memory corruption vulnerability attemptoffdropdropdrop
150941BROWSER-IEMicrosoft Edge scripting engine memory corruption vulnerability attemptoffdropdropdrop
150942OS-WINDOWSMicrosoft Windows graphics component privilege escalation attemptoffdropdropdrop
150943OS-WINDOWSMicrosoft Windows graphics component privilege escalation attemptoffdropdropdrop
150944FILE-OTHERVideoLAN VLC media player out-of-bounds read attemptoffoffoffdrop
150945FILE-OTHER VideoLAN VLC media player out-of-bounds read attemptoffoffoffdrop
150946SERVER-OTHERGnuTLS x509 certificate validation policy bypass attempt offoffoffdrop
150947INDICATOR-COMPROMISEPhpSploit backdoor communication attemptoffoffdropdrop
150948INDICATOR-COMPROMISEPhpSploit backdoor communication attemptoffoffdropdrop
150949INDICATOR-COMPROMISEPhpSploit backdoor installation attemptoffoffdropdrop
150950INDICATOR-COMPROMISEPHP backdoor communication attemptoffoffdropdrop
150951INDICATOR-COMPROMISEPhpSploit backdoor communication attemptoffoffdropdrop
150952INDICATOR-COMPROMISEPhpSploit backdoor communication attemptoffoffdropdrop
150953INDICATOR-COMPROMISEPhpSploit backdoor communication attemptoffoffdropdrop
150954INDICATOR-COMPROMISEPhpSploit backdoor communication attemptoffoffdropdrop
150955INDICATOR-COMPROMISEPhpSploit backdoor communication attemptoffoffdropdrop
150956FILE-OFFICEMicrosoft Office Excel MsoDrawingGroup record remote code execution attemptoffoffoffdrop
150957FILE-OFFICEMicrosoft Office Excel MsoDrawingGroup record remote code execution attemptoffoffoffdrop
150959FILE-OFFICEMicrosoft VBE6.dll stack corruption attemptoffoffoffdrop
150960FILE-IMAGEAdobe Photoshop CS5 gif file heap corruption attemptoffoffoffdrop
150961FILE-IMAGEAdobe Photoshop CS5 gif file heap corruption attemptoffoffoffdrop
150962FILE-OFFICEMicrosoft Office PowerPoint OfficeArt atom memory corruption attemptoffoffoffdrop
150963OS-WINDOWSMicrosoft Windows win32k.sys memory corruption attemptoffdropdropdrop
150964OS-WINDOWSMicrosoft Windows win32k.sys memory corruption attemptoffdropdropdrop
150965FILE-MULTIMEDIAMPlayer SMI file buffer overflow attemptoffoffoffdrop
150966OS-WINDOWSMicrosoft Windows CoreShellCOMServerRegistrar privilege escalation attemptoffdropdropdrop
150967OS-WINDOWSMicrosoft Windows CoreShellCOMServerRegistrar privilege escalation attemptoffdropdropdrop
150968SERVER-WEBAPPWordPress Crop Image arbitrary file write attemptoffoffoffdrop
150969OS-WINDOWSMicrosoft win32k driver buffer over read attemptoffdropdropdrop
150970OS-WINDOWSMicrosoft win32k driver buffer over read attemptoffdropdropdrop
150971OS-WINDOWSMicrosoft win32k driver buffer over read attemptoffdropdropdrop
150972OS-WINDOWSMicrosoft win32k driver buffer over read attemptoffdropdropdrop
150973OS-WINDOWSMicrosoft win32k driver buffer over read attemptoffdropdropdrop
150974OS-WINDOWSMicrosoft win32k driver buffer over read attemptoffdropdropdrop
150975FILE-OTHEROMRON CX-One arbitrary code execution attemptoffoffoffdrop
150976FILE-OTHEROMRON CX-One arbitrary code execution attemptoffoffoffdrop
150977SERVER-WEBAPPLCDS Laquis SCADA command injection attemptoffoffdropdrop
150978SERVER-WEBAPPLCDS Laquis SCADA command injection attemptoffoffdropdrop
150979SERVER-WEBAPPLCDS Laquis SCADA command injection attemptoffoffdropdrop
150980SERVER-WEBAPPLCDS Laquis SCADA command injection attemptoffoffdropdrop
150981SERVER-WEBAPPLCDS Laquis SCADA command injection attemptoffoffdropdrop
150982SERVER-WEBAPPLCDS Laquis SCADA command injection attemptoffoffdropdrop
150983SERVER-WEBAPPLCDS Laquis SCADA command injection attemptoffoffdropdrop
150984SERVER-WEBAPPLCDS Laquis SCADA command injection attemptoffoffdropdrop
150985FILE-IMAGEGraphicsMagick WMF use after free attemptoffoffoffdrop
150986FILE-IMAGEGraphicsMagick WMF use after free attemptoffoffoffdrop
150987OS-WINDOWSMicrosoft Windows CrmRpcSrvUnregister privilege escalation attemptoffoffdropdrop
150988OS-WINDOWSMicrosoft Windows CrmRpcSrvUnregister privilege escalation attemptoffoffdropdrop
150989MALWARE-CNCWin.Dropper.Clipbanker variant outbound connectionoffdropdropdrop
150990MALWARE-CNCUnix.Malware.ech0raix outbound connection attemptoffdropdropdrop
150991MALWARE-CNCUnix.Malware.ech0raix outbound connection attemptoffdropdropdrop
150992MALWARE-CNCUnix.Malware.ech0raix outbound connection attemptoffdropdropdrop
150993MALWARE-CNCUnix.Malware.ech0raix outbound connection attemptoffdropdropdrop
150994SERVER-WEBAPPPHP ProjectPier remote file include attemptoffoffoffdrop
150995SERVER-WEBAPPPHP ProjectPier remote file include attemptoffoffdropdrop
150996SERVER-WEBAPPPHP ProjectPier remote file include attemptoffoffdropdrop
150998FILE-OFFICEMicrosoft Office Outlook memory corruption attemptoffoffdropdrop
150999FILE-OFFICEMicrosoft Office Outlook memory corruption attemptoffoffdropdrop
151001OS-WINDOWSMicrosoft Windows privilege escalation attemptoffoffdropdrop
151002OS-WINDOWSMicrosoft Windows privilege escalation attemptoffoffdropdrop
151003OS-WINDOWSMicrosoft Windows privilege escalation attemptoffoffdropdrop
151004OS-WINDOWSMicrosoft Windows privilege escalation attemptoffoffdropdrop
151005OS-WINDOWSMicrosoft Windows privilege escalation attemptoffoffdropdrop
151006OS-WINDOWSMicrosoft Windows privilege escalation attemptoffoffdropdrop
151007OS-WINDOWSMicrosoft Windows privilege escalation attemptoffoffdropdrop
151008OS-WINDOWSMicrosoft Windows privilege escalation attemptoffoffdropdrop
151009OS-WINDOWSMicrosoft Windows privilege escalation attemptoffoffdropdrop
151010OS-WINDOWSMicrosoft Windows privilege escalation attemptoffoffdropdrop
151011OS-WINDOWSMicrosoft Windows privilege escalation attemptoffoffdropdrop
151012OS-WINDOWSMicrosoft Windows privilege escalation attemptoffoffdropdrop
151013OS-WINDOWSMicrosoft Windows privilege escalation attemptoffoffdropdrop
151014OS-WINDOWSMicrosoft Windows privilege escalation attemptoffoffdropdrop
151015OS-WINDOWSMicrosoft Windows PsmSrvDisconnect privilege escalation attemptoffoffdropdrop
151016OS-WINDOWSMicrosoft Windows PsmSrvDisconnect privilege escalation attemptoffoffdropdrop
151017PROTOCOL-OTHERLosant Arduino MQTT Client buffer overflow attemptoffoffoffdrop
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
150958SERVER-OTHERChicken of the VNC ServerInit denial of service attemptoffoffoffdrop
150997SERVER-OTHERNetwork Time Server denial of service attemptoffoffoffdrop
151000PROTOCOL-DNSPowerDNS Recursor query denial of service attemptoffoffoffdrop

Updated Rules:

Updated rules can be found at this link.