OS-WINDOWS -- Snort has detected traffic targeting vulnerabilities in a Windows-based operating system. This does not include browser traffic or other software on the OS, but attacks against the OS itself.
OS-WINDOWS Microsoft Windows Win32k SendMessageTimeout kernel information leak attempt
This event is generated when an attacker attempts to leak kernel memory via a vulnerability in Microsoft Windows' Win32k driver. Impact: Attempted Administrator Privilege Gain Details: This rule checks for attempts to leak kernel memory via a vulnerability in Microsoft Windows' Win32k driver. Ease of Attack:
No information provided
No public information
No known false positives
Cisco Talos Intelligence Group
No rule groups
CVE-2019-0628 |
Loading description
|