ET EXPLOIT Windows DNS Server RCE Attempt Inbound (CVE-2021-26877)
Sourceet/open
CreatedMarch 30, 2021
UpdatedMarch 30, 2021
Classificationattempted-admin
alert tcp any any -> $DNS_SERVERS 53 (msg:"ET EXPLOIT Windows DNS Server RCE Attempt Inbound (CVE-2021-26877)"; content:"|2e 95|"; offset:2; depth:2; content:"|00 10 00 01|"; distance:0; fast_pattern; byte_extract:1,5,data_len,relative; byte_test:1,>,data_len,0,relative; reference:cve,2021-26877; classtype:attempted-admin; sid:2032347; rev:2; metadata:attack_target DNS_Server, created_at 2021_03_30, cve CVE_2021_26877, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2021_03_30;)
References
| cve | 2021-26877 |
Metadata
attack targetDNS_Server
created at2021_03_30
deploymentInternal
confidenceMedium
signature severityMajor
tagDescription_Generated_By_Proofpoint_Nexus
updated at2021_03_30
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!