Back to Rule

Rule History

SID: 2016138 • Source: et/open

Versions (5)

Version DetailsCurrent

Rev: 7Jan 3, 2013, 12:00 PM

ET EXPLOIT Possible Internet Explorer Use-After-Free Inbound (CVE-2012-4792)

alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Possible Internet Explorer Use-After-Free Inbound (CVE-2012-4792)"; flow:established,from_server; file_data; content:"urn|3a|schemas-microsoft-com|3a|time"; nocase; content:"#default#time2"; content:"<t|3a|ANIMATECOLOR"; nocase; fast_pattern; content:"CollectGarbage"; nocase; content:"try"; distance:0; nocase; content:".values"; distance:0; nocase; pcre:"/^[\r\n\s\+]*?=.+?\}[\r\n\s]*?catch/Rsi"; reference:cve,2012-4792; reference:url,blog.exodusintel.com/2013/01/02/happy-new-year-analysis-of-cve-2012-4792/; classtype:attempted-user; sid:2016138; rev:7; metadata:created_at 2013_01_03, confidence Low, signature_severity Major, tag CISA_KEV, updated_at 2022_07_12;)

Jan 3, 2013, 12:00 PM

Jul 12, 2022, 12:00 PM

Sep 21, 2024, 3:00 AM

May 30, 2025, 12:04 AM

rules/emerging-exploit.rules