Rule Category

FILE-EXECUTABLE -- Snort detected traffic targeting vulnerabilites that are found in or delivered through executable files, regardless of platform. In those instances, Snort is able to correct traffic that has been altered.

Alert Message

FILE-EXECUTABLE Microsoft Windows NTFS privilege escalation attempt

Rule Explanation

This event is generated when an executable binary which exploits CVE-2018-8411 is detected. Impact: An attacker who is able to execute the binary on a vulnerable system could elevate their privileges and read sensitive information. Details: CVE-2018-8411 manifests in the NTFS component of the Windows kernel. This rule looks for executable code the triggers this vulnerability. Ease of Attack: Medium

What To Look For

No information provided

Known Usage

No public information

False Positives

No known false positives

Contributors

Cisco Talos Intelligence Group

Rule Groups

No rule groups

CVE

Additional Links

Rule Vulnerability

CVE Additional Information

This product uses data from the NVD API but is not endorsed or certified by the NVD.
CVE-2018-8411
Loading description