Versions (6)
Version DetailsCurrent
Rev: 2 • Jul 24, 2025, 5:44 PMATTACK [PTsecurity] MS Edge WScript Command Injection RCE (CVE-2018-8495)
alert http any any -> any any (msg:"ATTACK [PTsecurity] MS Edge WScript Command Injection RCE (CVE-2018-8495)"; flow:established, from_server; content:"wshfile:"; nocase; http_server_body; fast_pattern; content:".."; distance:0; http_server_body; content:".vbs"; distance:0; nocase; http_server_body; pcre:"/wshfile:[^\x22\x27\s]+(\\|\/)\.\.(\\|\/)[^\x22\x27\s]+\.vbs/Qi"; reference:cve, 2018-8495; reference:url, leucosite.com/Microsoft-Edge-RCE; reference:url, rules.ptsecurity.com; classtype:attempted-admin; sid:10003930; rev:2;)
Jul 24, 2025, 5:44 PM
Jul 24, 2025, 5:44 PM
Oct 16, 2025, 10:34 AM
Oct 16, 2025, 10:34 AM
rules/ptopen-attacks.rules