Rule Update
17-033 (July 11, 2017)
DESCRIPTION
* indicates a new version of an existing rule
Deep Packet Inspection Rules:
Apache OpenMeetings
1008267* - Apache OpenMeetings ZIP File Path Traversal Vulnerability (CVE-2016-0784)
DCERPC Services
1008432* - Microsoft Windows SMB Information Disclosure Vulnerability (CVE-2017-0267)
1008445* - Microsoft Windows Search Remote Code Execution Vulnerability (CVE-2017-8543)
DHCP Client
1004653* - ISC DHCP 'dhclient' Shell Characters In Response Remote Code Execution Vulnerability
HP Intelligent Management Center (IMC)
1008379* - HP Intelligent Management Center Service Information Disclosure Vulnerability (CVE-2017-5797)
Microsoft Office
1004312* - Identified Suspicious Microsoft Word Document
1008340* - Microsoft Office Remote Code Execution Vulnerability (CVE-2017-0243)
Port Mapper Windows
1001033* - Windows Port Mapper Decoder
Web Application Common
1008451 - ImageMagick 'MagickCore/blob.c' ReadOneJNGImage Assertion Vulnerability (CVE-2017-9142) - 1
1008450 - ImageMagick 'MagickCore/profile.c' ReadDDSImage Assertion Vulnerability (CVE-2017-9141) - 1
1008449 - ImageMagick ART File 'coders/art.c' ReadARTImage Denial Of Service Vulnerability (CVE-2017-9143) - 1
1008427* - ImageMagick Denial Of Service Vulnerability (CVE-2017-8346) - 1
1008383* - ImageMagick Heap Buffer Overflow Vulnerability (CVE-2016-9556)
1008388* - ImageMagick Use After Free Denial Of Service Vulnerability (CVE-2016-7906)
Web Client Common
1008387 - Foxit Reader ConvertToPDF TIFF Parsing Out Of Bounds Write Remote Code Execution Vulnerability
1008401 - Foxit Reader FlateDecode Use After Free Remote Code Execution Vulnerability
1008417 - Foxit Reader Stack Buffer Overflow Vulnerability
1008425 - ImageMagick 'MagickCore/blob.c' ReadOneJNGImage Assertion Vulnerability (CVE-2017-9142)
1008424 - ImageMagick 'MagickCore/profile.c' ReadDDSImage Assertion Vulnerability (CVE-2017-9141)
1008426 - ImageMagick ART File 'coders/art.c' ReadARTImage Denial Of Service Vulnerability (CVE-2017-9143)
1008377 - Microsoft Windows Media Format Remote Code Execution Vulnerability (CVE-2007-0064)
1008489 - Microsoft Windows Multiple Elevation Of Privilege Vulnerabilities (July-2017)
1008481 - Microsoft Windows Security Feature Bypass Vulnerability (CVE-2017-8592)
1008452 - Oracle Java Font Parsing Out-Of-Bounds Read Information Disclosure Vulnerability (CVE-2016-3443)
1008457* - Ransomware Erebus
Web Client Internet Explorer/Edge
1008439* - Microsoft Edge Memory Corruption Vulnerability (CVE-2017-8496)
1008486 - Microsoft Edge Remote Code Execution Vulnerability (CVE-2017-8617)
1008483 - Microsoft Edge Scripting Engine Memory Corruption Vulnerability (CVE-2017-8598)
1008484 - Microsoft Edge Scripting Engine Memory Corruption Vulnerability (CVE-2017-8601)
1008485 - Microsoft Edge Scripting Engine Memory Corruption Vulnerability (CVE-2017-8605)
1008487 - Microsoft Edge Scripting Engine Memory Corruption Vulnerability (CVE-2017-8619)
1008482 - Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2017-8594)
1008488 - Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability (CVE-2017-8618)
Web Server HTTPS
1008293 - Trend Micro Control Manager Download Multiple Directory Traversal Information Disclosure Vulnerabilities
Windows Services RPC Server DCERPC
1008479 - Identified Usage Of WMI Execute Methods - Server
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
Deep Packet Inspection Rules:
Apache OpenMeetings
1008267* - Apache OpenMeetings ZIP File Path Traversal Vulnerability (CVE-2016-0784)
DCERPC Services
1008432* - Microsoft Windows SMB Information Disclosure Vulnerability (CVE-2017-0267)
1008445* - Microsoft Windows Search Remote Code Execution Vulnerability (CVE-2017-8543)
DHCP Client
1004653* - ISC DHCP 'dhclient' Shell Characters In Response Remote Code Execution Vulnerability
HP Intelligent Management Center (IMC)
1008379* - HP Intelligent Management Center Service Information Disclosure Vulnerability (CVE-2017-5797)
Microsoft Office
1004312* - Identified Suspicious Microsoft Word Document
1008340* - Microsoft Office Remote Code Execution Vulnerability (CVE-2017-0243)
Port Mapper Windows
1001033* - Windows Port Mapper Decoder
Web Application Common
1008451 - ImageMagick 'MagickCore/blob.c' ReadOneJNGImage Assertion Vulnerability (CVE-2017-9142) - 1
1008450 - ImageMagick 'MagickCore/profile.c' ReadDDSImage Assertion Vulnerability (CVE-2017-9141) - 1
1008449 - ImageMagick ART File 'coders/art.c' ReadARTImage Denial Of Service Vulnerability (CVE-2017-9143) - 1
1008427* - ImageMagick Denial Of Service Vulnerability (CVE-2017-8346) - 1
1008383* - ImageMagick Heap Buffer Overflow Vulnerability (CVE-2016-9556)
1008388* - ImageMagick Use After Free Denial Of Service Vulnerability (CVE-2016-7906)
Web Client Common
1008387 - Foxit Reader ConvertToPDF TIFF Parsing Out Of Bounds Write Remote Code Execution Vulnerability
1008401 - Foxit Reader FlateDecode Use After Free Remote Code Execution Vulnerability
1008417 - Foxit Reader Stack Buffer Overflow Vulnerability
1008425 - ImageMagick 'MagickCore/blob.c' ReadOneJNGImage Assertion Vulnerability (CVE-2017-9142)
1008424 - ImageMagick 'MagickCore/profile.c' ReadDDSImage Assertion Vulnerability (CVE-2017-9141)
1008426 - ImageMagick ART File 'coders/art.c' ReadARTImage Denial Of Service Vulnerability (CVE-2017-9143)
1008377 - Microsoft Windows Media Format Remote Code Execution Vulnerability (CVE-2007-0064)
1008489 - Microsoft Windows Multiple Elevation Of Privilege Vulnerabilities (July-2017)
1008481 - Microsoft Windows Security Feature Bypass Vulnerability (CVE-2017-8592)
1008452 - Oracle Java Font Parsing Out-Of-Bounds Read Information Disclosure Vulnerability (CVE-2016-3443)
1008457* - Ransomware Erebus
Web Client Internet Explorer/Edge
1008439* - Microsoft Edge Memory Corruption Vulnerability (CVE-2017-8496)
1008486 - Microsoft Edge Remote Code Execution Vulnerability (CVE-2017-8617)
1008483 - Microsoft Edge Scripting Engine Memory Corruption Vulnerability (CVE-2017-8598)
1008484 - Microsoft Edge Scripting Engine Memory Corruption Vulnerability (CVE-2017-8601)
1008485 - Microsoft Edge Scripting Engine Memory Corruption Vulnerability (CVE-2017-8605)
1008487 - Microsoft Edge Scripting Engine Memory Corruption Vulnerability (CVE-2017-8619)
1008482 - Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2017-8594)
1008488 - Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability (CVE-2017-8618)
Web Server HTTPS
1008293 - Trend Micro Control Manager Download Multiple Directory Traversal Information Disclosure Vulnerabilities
Windows Services RPC Server DCERPC
1008479 - Identified Usage Of WMI Execute Methods - Server
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.