ZeroHour
Cisco Talospublished ()ingested

Rule release for today

mediumVulnerabilityimportance 30
Full article100 words · extracted from blog.talosintelligence.com · click to collapse

Thursday, October 22, 2009 16:49

A few modifications in this release, most notably a fix for a false positive issue that raised it's ugly head from the Microsoft Tuesday release.

Microsoft Security Advisory (MS09-059):
A vulnerability in the Microsoft Local Security Authority Subsystem Service (LSASS) may allow a remote attacker to cause a Denial of Service (Dos) against an affected system.

A previously released rule to detect attacks targeting this vulnerability has been modified to reduce the incidence of false positive events. It is included in this release and is identified with GID 3, SID 16167.

As always, changelogs: http://www.snort.org/vrt/advisories/2009/10/22/vrt-rules-2009-10-22.html

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/rule-release-for-today-october-22nd/