""ET WEB_CLIENT Internet Explorer Memory Corruption Vulnerability (CVE-2015-2444)""

SID: 2021709

Revision: 2

Class Type: attempted-user

Metadata: affected_product Web_Browsers, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2015_08_24, cve CVE_2015_2444, deployment Perimeter, confidence Medium, signature_severity Major, tag Web_Client_Attacks, updated_at 2015_08_25

Reference:

  • cve

  • 2015-2444

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: $HTTP_PORTS

Destination Network: $HOME_NET

Destination Port: any

Flow: from_server,established

Contents:

  • Value: "<style"

  • Value: "x-ua-compatible"

  • Value: "<button"

  • Value: "<label"

  • Value: "<form"

  • Value: "<meter"

  • Value: "<optgroup"

  • Value: "<meter"

  • Value: "-ms-behavior"

Within:

PCRE: "/^[\x22\x27]\scontent\s=\s[\x22\x27]\sIE\s=\s10/Rsi"

Special Options:

  • file_data

  • nocase

  • nocase

  • nocase

  • nocase

  • nocase

  • nocase

  • nocase

  • nocase

  • nocase

source