Sign In with your
Trend Micro Account
Need Help?
Need More Help?

Create a technical support case if you need further support.

Digital Vaccine #9041

    • Updated:
    • 6 Dec 2017
    • Product/Version:
    • TippingPoint Digital Vaccine
    • Platform:
Summary
Digital Vaccine #9041      December 5, 2017
Details
Public
Thank you for subscribing to Digital Vaccine updates brought to you by Trend Micro™ TippingPoint DVLabs.

New content is now available at the Threat Management Center (TMC): https://tmc.tippingpoint.com

SMS customers can update the Digital Vaccine through the SMS client. From the top line menu, you can open the "File > Download Digital Vaccine from TMC" menu item to detect and load the latest update.
 
System Requirements
The 3.2.0 DV will run on IPS devices with TOS v3.2.0 and above,  all NGFW and all TPS systems. The 4.0.0 DV will only run on the Virtual Threat Protection System (vTPS) appliance. Please note that vTPS does not currently support pre-disclosed ZDI filters.
 
Deployment of 3.2.0 DV
Customers with 10/110/330 systems that are running the 3.2.0 DV may see critical /usr partition usage errors in the system log. This is a benign, temporary message and the partition usage is immediately remedied as indicated by log messages following the error.
 
The Digital Vaccine can be manually downloaded from the following URLs:
https://tmc.tippingpoint.com/TMC/ViewPackage?parentFolderId=digital_vaccines&contentId=SIG_3.2.0_9041.pkg
https://tmc.tippingpoint.com/TMC/ViewPackage?parentFolderId=vsa_dv&contentId=SIG_VTPS_4.0.0_9041.pkg

Update Details

Table of Contents
--------------------------

Filters
 New Filters
 Modified Filters (logic changes)
 Modified Filters (metadata changes only)
 Removed Filters

Filters
----------------
 New Filters:


    29899: HTTP: Apache httpd mod_auth_digest Memory Access Denial-of-Service Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Vulnerabilities
      - Severity: Critical
      - Description: This filter detects an attempt to exploit a denial-of-service vulnerability in Apache.
      - Deployments:
        - Deployment: Default (Block / Notify)
        - Deployment: Performance-Optimized (Disabled)
      - References:
        - Bugtraq ID: 99569
        - Common Vulnerabilities and Exposures: CVE-2017-9788 CVSS 6.4

    29940: ZDI-CAN-5146: Zero Day Initiative Vulnerability (Adobe Acrobat Pro DC)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: Not available.
      - Requires: IPS N-Platform, NX-Platform, NGFW, or TPS models.
      - Category: Exploits
      - Severity: Critical
      - Description: This filter provides protection against exploitation of a zero-day vulnerability affecting Adobe Acrobat Pro DC.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify)

    29941: ZDI-CAN-5147: Zero Day Initiative Vulnerability (Adobe Acrobat Pro DC)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: Not available.
      - Requires: IPS N-Platform, NX-Platform, NGFW, or TPS models.
      - Category: Exploits
      - Severity: Critical
      - Description: This filter provides protection against exploitation of a zero-day vulnerability affecting Adobe Acrobat Pro DC.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify)

    29942: ZDI-CAN-5148: Zero Day Initiative Vulnerability (Adobe Acrobat Pro DC)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: Not available.
      - Requires: IPS N-Platform, NX-Platform, NGFW, or TPS models.
      - Category: Exploits
      - Severity: Critical
      - Description: This filter provides protection against exploitation of a zero-day vulnerability affecting Adobe Acrobat Pro DC.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify)

    29951: HTTP: XML void Type Usage
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Security Policy
      - Severity: Moderate
      - Description: This filter detects the usage of the primitive type void in XML.
      - Deployment: Not enabled by default in any deployment.
      - References:
        - Common Vulnerabilities and Exposures: CVE-2017-7957

    30052: HTTP: Supervisor XML-RPC Code Execution Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Vulnerabilities
      - Severity: Critical
      - Description: This filter detects an attempt to exploit a code execution vulnerability in Supervisor.
      - Deployments:
        - Deployment: Default (Block / Notify)
        - Deployment: Performance-Optimized (Disabled)
      - References:
        - Bugtraq ID: 100282
        - Common Vulnerabilities and Exposures: CVE-2017-11610 CVSS 9.0

    30054: HTTP: Electric Sheep Fencing (ESF) pfSense system_groupmanager.php Code Injection Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Vulnerabilities
      - Severity: Critical
      - Description: This filter detects attempts to exploit a code injection vulnerability in ESF pfSense firewall.
      - Deployments:
        - Deployment: Default (Block / Notify)
        - Deployment: Performance-Optimized (Disabled)

    30057: HTTP: Microsoft Office EQNEDT32 Buffer Overflow Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Category: Vulnerabilities
      - Severity: Critical
      - Description: This filter detects an attempt to exploit a buffer overflow vulnerability in Microsoft Office.
      - Deployments:
        - Deployment: Security-Optimized (Block / Notify)
      - References:
        - Bugtraq ID: 101757
        - Common Vulnerabilities and Exposures: CVE-2017-11882

  Modified Filters (logic changes):
    * = Enabled in Default deployments

    7801: Hypertext Transfer Protocol (HTTP)
      - IPS Version: Not available.
      - NGFW Version: 1.0.3 and after.
      - TPS Version: 4.0.0 and after in NGFW Persona mode.
      - vTPS Version: 4.0.1 and after in NGFW Persona mode.
      - Requires: Only NGFW models or TPS in NGFW Persona
      - Detection logic updated.

    7802: Telnet
      - IPS Version: Not available.
      - NGFW Version: 1.0.3 and after.
      - TPS Version: 4.0.0 and after in NGFW Persona mode.
      - vTPS Version: 4.0.1 and after in NGFW Persona mode.
      - Requires: Only NGFW models or TPS in NGFW Persona
      - Detection logic updated.

    7803: Domain Name System (DNS)
      - IPS Version: Not available.
      - NGFW Version: 1.0.3 and after.
      - TPS Version: 4.0.0 and after in NGFW Persona mode.
      - vTPS Version: 4.0.1 and after in NGFW Persona mode.
      - Requires: Only NGFW models or TPS in NGFW Persona
      - Detection logic updated.

    7804: File Transfer Protocol (FTP)
      - IPS Version: Not available.
      - NGFW Version: 1.0.3 and after.
      - TPS Version: 4.0.0 and after in NGFW Persona mode.
      - vTPS Version: 4.0.1 and after in NGFW Persona mode.
      - Requires: Only NGFW models or TPS in NGFW Persona
      - Detection logic updated.

    7805: Simple Network Management Protocol (SNMP)
      - IPS Version: Not available.
      - NGFW Version: 1.0.3 and after.
      - TPS Version: 4.0.0 and after in NGFW Persona mode.
      - vTPS Version: 4.0.1 and after in NGFW Persona mode.
      - Requires: Only NGFW models or TPS in NGFW Persona
      - Detection logic updated.

    7806: Server Message Block (SMB)
      - IPS Version: Not available.
      - NGFW Version: 1.0.3 and after.
      - TPS Version: 4.0.0 and after in NGFW Persona mode.
      - vTPS Version: 4.0.1 and after in NGFW Persona mode.
      - Requires: Only NGFW models or TPS in NGFW Persona
      - Detection logic updated.

    7807: Open Network Computing Remote Procedure Call (ONC-RPC)
      - IPS Version: Not available.
      - NGFW Version: 1.0.3 and after.
      - TPS Version: 4.0.0 and after in NGFW Persona mode.
      - vTPS Version: 4.0.1 and after in NGFW Persona mode.
      - Requires: Only NGFW models or TPS in NGFW Persona
      - Detection logic updated.

    7808: Microsoft Remote Procedure Call (MS-RPC)
      - IPS Version: Not available.
      - NGFW Version: 1.0.3 and after.
      - TPS Version: 4.0.0 and after in NGFW Persona mode.
      - vTPS Version: 4.0.1 and after in NGFW Persona mode.
      - Requires: Only NGFW models or TPS in NGFW Persona
      - Detection logic updated.

    7809: Virtual Network Computing (VNC)
      - IPS Version: Not available.
      - NGFW Version: 1.0.3 and after.
      - TPS Version: 4.0.0 and after in NGFW Persona mode.
      - vTPS Version: 4.0.1 and after in NGFW Persona mode.
      - Requires: Only NGFW models or TPS in NGFW Persona
      - Detection logic updated.

    7810: Simple Mail Transfer Protocol (SMTP)
      - IPS Version: Not available.
      - NGFW Version: 1.0.3 and after.
      - TPS Version: 4.0.0 and after in NGFW Persona mode.
      - vTPS Version: 4.0.1 and after in NGFW Persona mode.
      - Requires: Only NGFW models or TPS in NGFW Persona
      - Detection logic updated.

    7811: Internet Message Access Protocol (IMAP)
      - IPS Version: Not available.
      - NGFW Version: 1.0.3 and after.
      - TPS Version: 4.0.0 and after in NGFW Persona mode.
      - vTPS Version: 4.0.1 and after in NGFW Persona mode.
      - Requires: Only NGFW models or TPS in NGFW Persona
      - Detection logic updated.

    * 9868: HTTP: Adobe Multiple Products Remote Code Execution
      - IPS Version: 1.0.0 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 19701: HTTP: Microsoft Internet Explorer Use-After-Free Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 20095: HTTP: Adobe Flash Malicious File Download
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 20188: HTTP: Microsoft Internet Explorer Buffer Overflow Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    20319: HTTP: Microsoft TrueType Font Parsing Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    20322: HTTP: Microsoft Windows Malicious OpenType Font File Download
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    20325: HTTP: TrueType Font glfy table Parsing Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 20343: HTTP: Adobe Flash Player Sandbox Bypass Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 20417: HTTP: Foxit Multiple Products PNG To PDF Conversion Heap Buffer Overflow Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    20438: HTTP: Adobe Flash Malicious File Download
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 20623: HTTP: Adobe Reader DC U3D Use-After-Free Vulnerability (ZDI-15-508)
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    21684: HTTP: Microsoft Word Buffer Overflow Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 21774: HTTP: Microsoft Internet Explorer and Edge CACPWrap Use-After-Free Vulnerability (ZDI-16-158)
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    22076: HTTP: Microsoft Excel Memory Corruption Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    22085: SMTP: Microsoft Outlook Arbitrary Code Execution Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    22224: HTTP: Adobe FlashPlayer Null Check Memory Corruption Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 22278: HTTP: Adobe Flash Player Null Check Memory Corruption Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 22303: HTTP: Microsoft Windows COMSVCS.DLL Insecure Library Loading Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 22441: HTTP: Microsoft Silverlight Out-of-Bounds Memory Access Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    22627: TCP: Hewlett Packard Enterprise Data Protector EXEC_SCRIPT Buffer Overflow Vulnerability(ZDI-16-247)
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    22690: HTTP: Microsoft Windows Journal Use-After-Free Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 22707: HTTP: Oracle Java Font Parsing Out-of-Bounds Read Vulnerability (ZDI-16-376)
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    22736: HTTP: Foxit Reader Use-After-Free Vulnerability (ZDI-16-027)
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 22877: HTTP: Microsoft Word Frame Memory Corruption Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 23796: HTTP: Panasonic FPWIN Pro Type Confusion Vulnerability (ZDI-16-334)
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    23901: HTTP: Microsoft Windows Malicious OpenType Font File Download
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 23910: HTTP: Microsoft Word wwlib Buffer Overflow Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 24068: HTTP: Adobe Reader CoolType Buffer Overflow Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 24085: HTTP: Adobe Reader PICT Buffer Overflow Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.

    * 24088: HTTP: Microsoft Windows OpenType Compact Font Format Code Execution Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 24115: HTTP: Microsoft Internet Explorer CMediaEngine Use-After-Free Vulnerability (ZDI-16-230)
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 24137: HTTP: Microsoft Windows OLE Object Memory Corruption Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 24255: HTTP: Adobe Flash SWF Parser Memory Corruption Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    24387: HTTP: Adobe Reader DC FlateDecode Use-After-Free Vulnerability (ZDI-16-328)
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 24477: HTTP: Adobe Acrobat Reader DC FlateDecode Use-After-Free Vulnerability (ZDI-16-420)
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 24478: ZDI-CAN-3664: Zero Day Initiative Vulnerability (Adobe Digital Editions)
      - IPS Version: 3.2.0 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: Not available.
      - Requires: IPS N-Platform, NX-Platform, NGFW, or TPS models.
      - Detection logic updated.

    * 24765: HTTP: Microsoft Internet Explorer EMF Out-of-Bounds Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    24846: HTTP: Adobe Flash loadSound Use-After-Free Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 24904: HTTP: Adobe Reader DC FlateDecode Parsing Out-Of-Bounds Read Vulnerability (ZDI-16-421)
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 24925: HTTP: Solarwinds Virtualization Manager Apache Commons Collections Deserialization Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    24962: HTTP: Symantec Multiple Products Code Execution Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 24990: HTTP: Microsoft Windows Information Disclosure Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 24994: HTTP: Microsoft Excel bookViews Memory Corruption Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    25009: HTTP: Adobe Flash Malformed Tag Memory Corruption Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    25010: HTTP: Adobe Flash Malformed Tag Memory Corruption Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    25011: HTTP: Adobe Flash SceneAndFormatData Tag Memory Corruption Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    25016: HTTP: Symantec Multiple Products Dec2LHA Buffer Overflow Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 25236: HTTP: Microsoft Windows TTF Memory Corruption Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    25372: HTTP: Delta Industrial Automation WPLSoft DVP File Parsing Buffer Overflow Vulnerability(ZDI-16-661)
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 25447: HTTP: Adobe Reader DC JPEG2000 Parsing Information Disclosure Vulnerability (ZDI-17-242)
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 25493: HTTP: IBM WebSphere WASPostParam cookie Untrusted Java Deserialization Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 25721: HTTP: Microsoft Windows NtGdiSetBitmapAttributes Privilege Escalation Vulnerability (ZDI-16-592)
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 25729: HTTP: Microsoft Windows NtSetWindowLongPtr Privilege Escalation Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    25832: HTTP: Adobe Reader DC JPEG2000 Parsing Buffer Overflow Vulnerability (ZDI-17-003)
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    26105: HTTP: Microsoft Office and Internet Explorer Hlink Memory Corruption Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    26179: HTTP: Microsoft Office WMF Memory Corruption Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 26182: HTTP: Microsoft Office .doc Information Disclosure Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 26271: HTTP: Adobe Digital Editions FlateDecode Out-of-Bounds Read Vulnerability (ZDI-17-102)
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 26272: HTTP: Adobe Digital Editions FlateDecode Out-of-Bounds Read Vulnerability (ZDI-17-103)
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 26274: HTTP: Adobe Digital Editions PDF Font Parsing Out-of-Bounds Read Vulnerability (ZDI-17-104)
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 26277: HTTP: Adobe Digital Editions PDF Font Parsing Out-of-Bounds Read Vulnerability (ZDI-17-107)
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 26410: HTTP: Microsoft Word RTF Memory Corruption Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 26489: HTTP: Adobe Reader DC ImageConversion JPEG Parsing Buffer Overflow Vulnerability (ZDI-17-023)
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 26521: HTTP: Adobe Reader DC PRC Parsing Memory Corruption Vulnerability (ZDI-17-249)
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 27051: HTTP: Microsoft Edge JavascriptArray Out-of-Bounds Write Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 27748: HTTP: Adobe Acrobat Pro DC ImageConversion EMF Memory Corruption Vulnerability (ZDI-17-276)
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 27810: HTTP: Microsoft Internet Explorer ArrayBuffer Buffer Overflow Vulnerability (ZDI-17-401)
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 27821: HTTP: Adobe Acrobat Pro DC ImageConversion EMF Parsing Out-Of-Bounds Write Vulnerability(ZDI-17-607)
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 28199: HTTP: Microsoft Windows Kernel Information Disclosure Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 28610: HTTP: Microsoft Embedded OpenType EOT Font Integer Overflow Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    28730: HTTP: Adobe Acrobat Pro DC ImageConversion Memory Corruption Vulnerability (ZDI-17-618,ZDI-17-626)
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 28731: HTTP: Adobe Acrobat Pro DC ImageConversion EMF Parsing Out-Of-Bounds Write Vulnerability(ZDI-17-617)
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    28732: HTTP: Adobe Acrobat Pro DC ImageConversion Information Disclosure Vulnerability (ZDI-17-619)
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 28734: HTTP: Adobe Acrobat Pro DC XFA Type Confusion Vulnerability (ZDI-17-627)
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 28736: HTTP: Microsoft Windows PDF Library JPEG2000 Memory Corruption Vulnerability (ZDI-17-728)
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 28813: HTTP: Adobe Reader DC FlateDecode stream Parsing Out-of-Bounds Read Vulnerability (ZDI-16-491)
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "28813: HTTP: Adobe Reader DC FlateDecode stream Parsing Out-Of-Bounds Read Vulnerability (ZDI-16-491)".
      - Description updated.
      - Detection logic updated.

    29364: HTTP: Adobe Acrobat Pro DC ImageConversion Memory Corruption Vulnerability (ZDI-17-621)
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    29367: HTTP: Adobe Acrobat Pro DC ImageConversion Information Disclosure Vulnerability (ZDI-17-625)
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    29368: HTTP: Adobe Acrobat Pro DC ImageConversion Memory Corruption Vulnerability (ZDI-17-629)
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 29766: HTTP: Microsoft Office OOXML Type Confusion Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.

    * 29796: ZDI-CAN-5114: Zero Day Initiative Vulnerability (Microsoft Chakra)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: Not available.
      - Requires: IPS N-Platform, NX-Platform, NGFW, or TPS models.
      - Detection logic updated.

    * 29799: ZDI-CAN-5115: Zero Day Initiative Vulnerability (Microsoft Chakra)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: Not available.
      - Requires: IPS N-Platform, NX-Platform, NGFW, or TPS models.
      - Detection logic updated.

    * 29813: HTTP: Fuji Electric V-Server VPR File Parsing Memory Corruption Vulnerability (ZDI-17-485)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Detection logic updated.

    * 29905: PWN2OWN ZDI-CAN-5347: Zero Day Initiative Vulnerability (Huawei Browser)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: Not available.
      - Requires: IPS N-Platform, NX-Platform, NGFW, or TPS models.
      - Detection logic updated.

    * 29911: PWN2OWN ZDI-CAN-5353: Zero Day Initiative Vulnerability (Apple Safari)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: Not available.
      - Requires: IPS N-Platform, NX-Platform, NGFW, or TPS models.
      - Detection logic updated.

    * 29924: HTTP: Microsoft Windows Kernel Privilege Escalation Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 29929: HTTP: Microsoft Word RTF Memory Corruption Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 29931: HTTP: Microsoft Edge getOwnPropertyDescriptor Use-After-Free Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 30030: HTTP: Adobe Acrobat Reader Font processing Out-of-Bounds Memory Access Vulnerability
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    * 30614: HTTP: Symantec AntiVirus Engine Decomposer MSPACK Denial-of-Service Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

    39123: HTTP: PHP exif_process_user_comment Denial-of-Service Vulnerability
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Detection logic updated.

  Modified Filters (metadata changes only):
    * = Enabled in Default deployments

    28921: HTTP: Foxit Reader saveAs Arbitrary File Write Vulnerability (ZDI-17-692)
      - IPS Version: 3.2.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Description updated.
      - Vulnerability references updated.

    28924: HTTP: Adobe Acrobat Pro DC iframe Information Disclosure Vulnerability (ZDI-17-927)
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "28924: HTTP: Adobe Acrobat Pro DC iframe Same Origin Policy Bypass Information Disclosure Vulnerability".
      - Description updated.
      - Vulnerability references updated.

    29744: HTTP: Microsoft Windows JavaScript Array Use-After-Free Vulnerability (ZDI-17-914)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "29744: HTTP: Microsoft Windows JavaScript Array Use-After-Free Vulnerability".
      - Description updated.
      - Vulnerability references updated.

    * 29784: HTTP: Microsoft Excel Use-After-Free Vulnerability (ZDI-17-915)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "29784: HTTP: Microsoft Excel Use-After-Free Vulnerability".
      - Description updated.
      - Vulnerability references updated.

    * 29794: HTTP: Microsoft Windows VBScript Join Function Integer Overflow Vulnerability (ZDI-17-916)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "29794: HTTP: Microsoft Windows VBScript Join Function Integer Overflow Vulnerability".
      - Description updated.
      - Vulnerability references updated.

    * 29832: HTTP: Microsoft Chakra Regular Expression Integer Overflow Vulnerability (ZDI-17-912)
      - IPS Version: 3.6.2 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Name changed from "29832: HTTP: Microsoft Chakra Regular Expression Integer Overflow Vulnerability".
      - Description updated.
      - Vulnerability references updated.

    39121: HTTP: Ecava IntegraXor getdata name SQL Injection Vulnerability (ZDI-17-058)
      - IPS Version: 3.1.3 and after.
      - NGFW Version: 1.0.0 and after.
      - TPS Version: 4.0.0 and after.
      - vTPS Version: 4.0.1 and after.
      - Miscellaneous modification.

  Removed Filters: None
  
Top of the Page
Premium
Internal
Rating:
Category:
Configure; Troubleshoot; Deploy
Solution Id:
TP000096737
Feedback
Did this article help you?

Thank you for your feedback!

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.

If you need additional help, you may try to contact the support team. Contact Support


To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.