Back to Rule

Rule History

SID: 2016137 • Source: et/open

Versions (4)

Version DetailsCurrent

Rev: 5Dec 31, 2012, 12:00 PM

ET EXPLOIT EIP in URI M1 (CVE-2012-4792)

alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET EXPLOIT EIP in URI M1 (CVE-2012-4792)"; flow:established,to_server; http.uri.raw; content:"/%E0%B4%8C%E1%88%92"; fast_pattern; http.header; content:"MSIE 8.0|3b|"; reference:cve,2012-4792; reference:url,github.com/rapid7/metasploit-framework/commit/6cb9106218bde56fc5e8d72c66fbba9f11c24449; reference:url,eromang.zataz.com/2012/12/29/attack-and-ie-0day-informations-used-against-council-on-foreign-relations/; classtype:attempted-user; sid:2016137; rev:5; metadata:created_at 2012_12_31, signature_severity Major, tag CISA_KEV, updated_at 2022_06_13;)

Dec 31, 2012, 12:00 PM

Jun 13, 2022, 12:00 PM

Sep 21, 2024, 3:00 AM

May 30, 2025, 12:04 AM

rules/emerging-exploit.rules