Think you have a false positive on this rule?

Sid 1-48519

Message

BROWSER-IE Microsoft Edge buffer overflow attempt

Summary

This event is generated when a buffer overflow is detected in Microsoft Edge which could lead to remote code execution.

Impact

Attempted User Privilege Gain

CVE-2018-8634:

CVSS base score 8.8

CVSS impact score 5.9

CVSS exploitability score 2.8

Confidentiality Impact HIGH

Integrity Impact HIGH

Availability Impact HIGH

Detailed information

CVE-2018-8634: A remote code execution vulnerability exists in Windows where Microsoft text-to-speech fails to properly handle objects in the memory, aka "Microsoft Text-To-Speech Remote Code Execution Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 10 Servers.

Affected systems

  • microsoft windows_10 -
  • microsoft windows_10 1607
  • microsoft windows_10 1703
  • microsoft windows_10 1709
  • microsoft windows_10 1803
  • microsoft windows_10 1809
  • microsoft windowsserver2016 -
  • microsoft windowsserver2016 1709
  • microsoft windowsserver2016 1803
  • microsoft windowsserver2019 -

Ease of attack

CVE-2018-8634:

Access Vector

Access Complexity

Authentication

False positives

False negatives

Corrective action

Contributors

  • Cisco's Talos Intelligence Group

Additional References

  • portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2018-8634