Snort mailing list archives

Snort Subscriber Rules Update 2021-11-25


From: Research <research () sourcefire com>
Date: Thu, 25 Nov 2021 21:18:28 GMT

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


Talos Snort Subscriber Rules Update

Synopsis:
This release adds and modifies rules in several categories.

Details:
Microsoft Vulnerability CVE-2021-42321:
A remote code execution vulnerability exists in Microsoft Exchange
Server for which exploit code is publicly available.

Rules to detect attacks targeting this vulnerability are included in
this release and are identified with GID 1, SIDs 58637 through 58639. 

Talos has added and modified multiple rules in the server-other rule
sets to provide coverage for emerging threats from these technologies.


For a complete list of new and modified rules please see:

https://www.snort.org/advisories
-----BEGIN PGP SIGNATURE-----

iQIcBAEBAgAGBQJhn/2iAAoJEGCbAk8rPt0HISYP/jG9fybyUI+60Q1rYhlVS4JR
XPQtJd51iGiW/nzBzXlJ48eXa2mGurmeBBRg786xpO4HfVpvMy8IZAbnRyceKJ5t
kSG2/7KWWHDTfLLxvqpOm5jXRcdyoosji0UM1nMlK9PdmmKfPdkjTD7z+JjJBiPQ
GMA9W7Wl4XQUNCug/GbZgPnrB3ARQUVVy0lXrZnr8okX6kSm76SSnL0oMFGy1x7f
j35kicUC0rE0DHcSzFrFRVwm7bJZQ9FOWTiUe6OVd5NiKDdxWDC54gzeRbDxLMrR
CWnjcQ1+eqH7COqyko6ljYZCV5/ztpEJ88pc5NSDFPnNsnGiNjIIG2qXn+s7uDGh
HBjPBcaj3LIk60XzqWS5vqWTRpiiazujoEgOO+THdBMba6GSAfJZ8BBYsoYGcMlC
tdh0TZNiYbZDxXHonrk7cBFC27wKIEfyaAXLjW13AsEAvqVaNkNWg2Zm5sGXLUfv
IbX9tIx38y/+NnrSkXJffLir2jfbboTKe/VbyKRTF7/liHPTHD8P8q7FhdKhOkar
PSK8kt8rSQpg87yNVncgvhy4OsBQg1pxc5InGxfdgrxcmLGlnl1LqvVFqjNxsEq7
HX+IfBbakjAG9o1Y7NiEu6GyT7qfV8JITa7Y5eZCrHkK6cSTm86wS9vajeN29TKR
J5Vupks/t2QZjyatr5iC
=eh7D
-----END PGP SIGNATURE-----

_______________________________________________
Snort-sigs mailing list
Snort-sigs () lists snort org
https://lists.snort.org/mailman/listinfo/snort-sigs

Please visit http://blog.snort.org for the latest news about Snort!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a 
href=" https://snort.org/downloads/#rule-downloads";>emerging threats</a>!


Current thread: