Rule Update
19-029 (May 21, 2019)
Publish date: May 21, 2019
DESCRIPTION
* indicates a new version of an existing rule
Deep Packet Inspection Rules:
DCERPC Services
1006906* - Identified Usage Of PsExec Command Line Tool
HP Intelligent Management Center Dbman
1009043 - HPE Intelligent Management Center 'dbman' FileTrans Arbitrary File Write Vulnerability (CVE-2017-5822)
1009637 - HPE Intelligent Management Center 'dbman' Stack Buffer Overflow Vulnerability (CVE-2018-7115)
HP OpenView Network Node Manager Web
1004280* - HP OpenView NNM ovwebsnmpsrv.exe Command Line Argument Buffer Overflow
Remote Desktop Protocol Server
1009749* - Microsoft Windows Remote Desktop Services Remote Code Execution Vulnerability (CVE-2019-0708)
Web Application Common
1009687 - Ghostscript Remote Code Execution Vulnerability (CVE-2016-10218) - 1
1009691 - Ghostscript Remote Code Execution Vulnerability (CVE-2016-10220) - 1
1009423 - ImageMagick Multiple Security Vulnerabilities (Server) - 26
Web Client Common
1009234 - Foxit Reader Multiple Security Vulnerabilities - 7
1009686 - Ghostscript Remote Code Execution Vulnerability (CVE-2016-10218)
1009690 - Ghostscript Remote Code Execution Vulnerability (CVE-2016-10220)
1009422 - ImageMagick Multiple Security Vulnerabilities (Client) - 26
1009539* - Microsoft Windows Multiple GDI Information Disclosure Vulnerabilities (Feb 2019)
1009582* - Microsoft Windows Win32k Elevation Of Privilege Vulnerability (CVE-2019-0808)
1009698 - Microsoft Word Information Disclosure Vulnerability (CVE-2019-0561)
Web Client Internet Explorer/Edge
1009411* - Microsoft Edge Chakra Scripting Engine Memory Corruption Vulnerability (CVE-2018-8617)
1009463* - Microsoft Edge Chakra Scripting Engine Memory Corruption Vulnerability (CVE-2019-0539)
1009464* - Microsoft Internet Explorer Remote Code Execution Vulnerability (CVE-2019-0541)
Web Server SAP
1009715* - SAP Gateway 'gw/acl_mode' Command Injection Vulnerability (10KBLAZE)
Zoho ManageEngine
1009399 - Zoho ManageEngine OpManager 'oputilsServlet' Authentication Bypass (CVE-2018-17283)
Integrity Monitoring Rules:
1007295* - Application - chrony
1003168* - Unix - Open Port Monitor
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
Deep Packet Inspection Rules:
DCERPC Services
1006906* - Identified Usage Of PsExec Command Line Tool
HP Intelligent Management Center Dbman
1009043 - HPE Intelligent Management Center 'dbman' FileTrans Arbitrary File Write Vulnerability (CVE-2017-5822)
1009637 - HPE Intelligent Management Center 'dbman' Stack Buffer Overflow Vulnerability (CVE-2018-7115)
HP OpenView Network Node Manager Web
1004280* - HP OpenView NNM ovwebsnmpsrv.exe Command Line Argument Buffer Overflow
Remote Desktop Protocol Server
1009749* - Microsoft Windows Remote Desktop Services Remote Code Execution Vulnerability (CVE-2019-0708)
Web Application Common
1009687 - Ghostscript Remote Code Execution Vulnerability (CVE-2016-10218) - 1
1009691 - Ghostscript Remote Code Execution Vulnerability (CVE-2016-10220) - 1
1009423 - ImageMagick Multiple Security Vulnerabilities (Server) - 26
Web Client Common
1009234 - Foxit Reader Multiple Security Vulnerabilities - 7
1009686 - Ghostscript Remote Code Execution Vulnerability (CVE-2016-10218)
1009690 - Ghostscript Remote Code Execution Vulnerability (CVE-2016-10220)
1009422 - ImageMagick Multiple Security Vulnerabilities (Client) - 26
1009539* - Microsoft Windows Multiple GDI Information Disclosure Vulnerabilities (Feb 2019)
1009582* - Microsoft Windows Win32k Elevation Of Privilege Vulnerability (CVE-2019-0808)
1009698 - Microsoft Word Information Disclosure Vulnerability (CVE-2019-0561)
Web Client Internet Explorer/Edge
1009411* - Microsoft Edge Chakra Scripting Engine Memory Corruption Vulnerability (CVE-2018-8617)
1009463* - Microsoft Edge Chakra Scripting Engine Memory Corruption Vulnerability (CVE-2019-0539)
1009464* - Microsoft Internet Explorer Remote Code Execution Vulnerability (CVE-2019-0541)
Web Server SAP
1009715* - SAP Gateway 'gw/acl_mode' Command Injection Vulnerability (10KBLAZE)
Zoho ManageEngine
1009399 - Zoho ManageEngine OpManager 'oputilsServlet' Authentication Bypass (CVE-2018-17283)
Integrity Monitoring Rules:
1007295* - Application - chrony
1003168* - Unix - Open Port Monitor
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
Featured Stories
- The Mirage of AI Programming: Hallucinations and Code IntegrityThe adoption of large language models (LLMs) and Generative Pre-trained Transformers (GPTs), such as ChatGPT, by leading firms like Microsoft, Nuance, Mix and Google CCAI Insights, drives the industry towards a series of transformative changes. As the use of these new technologies becomes prevalent, it is important to understand their key behavior, advantages, and the risks they present.Read more
- Open RAN: Attack of the xAppsThis article discusses two O-RAN vulnerabilities that attackers can exploit. One vulnerability stems from insufficient access control, and the other arises from faulty message handlingRead more
- A Closer Exploration of Residential Proxies and CAPTCHA-Breaking ServicesThis article, the final part of a two-part series, focuses on the details of our technical findings and analyses of select residential proxies and CAPTCHA-solving services.Read more
- How Residential Proxies and CAPTCHA-Solving Services Become Agents of AbuseThis article, the first of a two-part series, provides insights on how abusers and cybercriminals use residential proxies and CAPTCHA-solving services to enable bots, scrapers, and stuffers, and proposes security countermeasures for organizations.Read more